← certSIGN cases
Bugzilla #1398243
Certificate Problem Report
certSIGN: Non-BR-Compliant OCSP Responders
RESOLVED
FIXED
certSIGN
AI Summary
The certSIGN CA faced issues with its OCSP responders not complying with the Baseline Requirements (BRs), specifically responding with a 'good' status for unissued certificates. The problem was identified through discussions in the Mozilla security policy forum. certSIGN acknowledged the issues and took corrective actions, including fixing a misconfiguration and updating their OCSP monitoring service. They committed to improving their processes to prevent future non-compliance, including consulting with auditors and enhancing their testing procedures.
Chronology
- certSIGN became aware of the OCSP issues via a discussion in the Mozilla security policy forum.
- The misconfiguration for the OCSP for certSIGN Enterprise CA was fixed.
- certSIGN updated their OCSP responder to comply with the BRs for the ROOT CA.
- The issue was resolved, and all questions were answered.
Participants
Cristian Garabet
Kathleen Wilson
Ryan Sleevi
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
Consorci AOC: Non-BR-Compliant Certificate Issuance
Staat der Nederlandend / PKIoverheid: Non-BR-Compliant OCSP Responders
Visa: Non-BR-Compliant Certificate Issuance
Disig: Non-BR-Compliant OCSP Responders
D-TRUST: Non-BR-Compliant Certificate Issuance
DocuSign/Keynectis: Non-BR-Compliant OCSP Responders
Camerfirma: Non-BR-Compliant Certificate Issuance
GlobalSign: Non-BR-Compliant Certificate Issuance - metadata-only subject fields