← Disig, a.s. cases
Bugzilla #1398242
Incident
Disig: Non-BR-Compliant OCSP Responders
RESOLVED
FIXED
Disig, a.s.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
Disig, a.s. reported a compliance issue regarding their OCSP responders, which were found to be returning 'good' status for unissued certificates, violating section 4.9.10 of the Baseline Requirements. The issue was discovered through a problem report submitted to their Problem Reporting Mechanism. Disig took immediate action to investigate and rectify the misconfiguration, which was resolved by August 31, 2017. The CA has since implemented measures to ensure compliance with the Baseline Requirements and prevent future occurrences of similar issues.
Chronology
- Disig fixed the OCSP responder misconfiguration.
Thread Activity
- Mozilla representative — Reported issues with OCSP responders for Disig.
- Disig, a.s. — Provided a timeline of actions taken in response to the OCSP issue.
- Community commenter — Requested further details on the misconfiguration and mitigation steps.
- Disig, a.s. — Explained the misconfiguration and steps taken to ensure compliance.
- Disig, a.s. — Described corrective actions to prevent future incidents.
Participants
Mozilla representative
Disig, a.s.
Community commenter
External References
Similar Local Cases
Disig: Non-BR-Compliant Certificate Issuance
Disig: Failure to Respond to Jun 2023 Apple Root Program Survey
Firmaprofesional: Non-BR-Compliant OCSP Responders
GlobalSign: Non-BR-Compliant Certificate Issuance -- double-dots in dnsName
GlobalSign: Non-BR-Compliant Certificate Issuance -- RSA key smaller than 2048 bits
SECOM: Non-BR-Compliant Certificate Issuance
DigiCert / CTJ: Metadata in OU fields, Reserved IP Address
GlobalSign: Non-BR-Compliant Certificate Issuance - metadata-only subject fields