certSIGN: Non-BR-Compliant OCSP Responders
This case concerns problems with certSIGN OCSP responders that could return a “good” status for unissued certificates, which Mozilla cited as a Baseline Requirements issue (BR section 4.9.10, effective 2013-08-01). The issue was raised in the mozilla.dev.security.policy forum and certSIGN was asked to provide an incident report. certSIGN stated that the Enterprise CA Class 3 G2 OCSP problem was due to a misconfiguration and was fixed on 2017-08-30, and that it would update internal OCSP monitoring to include tests for unissued certificates by 2017-09-15. For the Root CA OCSP responder, certSIGN said it was due to a software limitation and would be fixed by 2017-09-15, later stating it had misinterpreted the BR requirement and that the Root CA system being offline contributed to the misunderstanding. certSIGN also reported that after updating the OCSP responder for the Root CA, it encountered a software bug where some valid certificates returned OCSP responses that appeared “not-issued” (REVOKED with revocationTime January 1, 1970), and said monitoring identified and corrected the issue. The bug was ultimately resolved as FIXED after certSIGN provided further responses and the issue was described as fixed.
- certSIGN became aware of OCSP responder non-compliance via discussion in mozilla.dev.security.policy.
- certSIGN fixed the OCSP issue for certSIGN Enterprise CA Class 3 G2.
- certSIGN planned updates to OCSP monitoring and the Root CA OCSP responder to address the unissued-certificate handling requirement.
- The issue was reported as fixed and the bug was resolved.
- Mozilla representative — Requested an incident report, citing BR section 4.9.10 and stating OCSP responders must not respond with “good” for unissued certificates.
- certSIGN — Acknowledged the issues, said one was fixed the day after reporting, and that the other would be fixed by 2017-09-15 with a full report on Monday.
- certSIGN — Provided an incident report describing the Enterprise CA Class 3 G2 OCSP issue as misconfiguration fixed on 2017-08-30, and the Root CA OCSP issue as a software limitation to be fixed by 2017-09-15, including monitoring/test updates.
- Community commenter — Asked for more complete root-cause analysis, especially why tests for the BR change were missing and what systemic steps would prevent recurrence.
- certSIGN — Explained it was not aware of the Root CA OCSP requirement as interpreted, described monitoring and an encountered software bug after updating the Root CA OCSP responder, and stated everything was in order with careful monitoring.
- Community commenter — Requested a fuller response, emphasizing that the immediate fix did not provide a structural outline for future detection/mitigation and proposing deeper “why” analysis.
- certSIGN — Responded with additional root-cause framing and stated it would consult more frequently with auditors on BR changes and update its change management process.
- Mozilla representative — Said the response to comment #5 was not complete and asked for a fuller root-cause analysis.
- certSIGN — Provided further root-cause analysis, stating misinterpretation of BR requirements and lack of awareness until now for the Root CA, and describing the Enterprise CA issue as misconfiguration after migration plus missing monitoring tests, along with a mitigation via cross-check verification.
- Fastly representative — Stated the issue was fixed and resolved the bug.