← DocuSign (OpenTrust/Keynectis) cases
Bugzilla #1398247 Ca Certificate Compliance

DocuSign/Keynectis: Non-BR-Compliant OCSP Responders

RESOLVED FIXED DocuSign (OpenTrust/Keynectis)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case involves DocuSign (Keynectis) disclosing a compliance issue regarding their OCSP responders, which were found to be non-compliant with the Baseline Requirements (BRs). The issue was initially reported in the mozilla.dev.security.policy forum, highlighting that OCSP responders must not respond with a 'good' status for unissued certificates. The CA acknowledged the problem and provided a timeline for remediation, including updates to their OCSP responder configuration. The OCSP responder has since been updated to comply with BR requirements, and an incident report detailing the timeline and corrective actions has been submitted.

Model: gpt-4o-mini Generated: 2026-06-13 17:09 UTC Revised: 2026-06-16 18:35 UTC Confidence: 0.85 22 comments
Chronology
  1. Initial report of non-compliance with OCSP responders
  2. OCSP responder updated to be BR-compliant
  3. Incident report submitted detailing the compliance issue and remediation steps
  4. New audit for the Certplus Class 2 Primary CA received and processed
Thread Activity
  1. Mozilla representative — Problems have been found with OCSP responders for this CA, and reported in the mozilla.dev.security.policy forum.
  2. Docusign representative — This intermediate CA is offline and used for the Adobe AATL program.
  3. Docusign representative — The OCSP responder has been updated to be BR-compliant.
  4. Docusign representative — Here's the incident report detailing the timeline and steps taken.
  5. Fastly representative — A new audit for the Certplus Class 2 Primary CA has been received and processed.
Participants
Mozilla representative Docusign representative Community commenter Fastly representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1390994 RESOLVED Ca Certificate Compliance Opened 2017-08-16 · Closed 2023-02-22 · 100% similar
DocuSign/Keynectis: Non-BR-Compliant Certificate Issuance
#1398240 RESOLVED Ca Certificate Compliance Incident Opened 2017-09-08 · Closed 2023-02-22 · 91% similar
Firmaprofesional: Non-BR-Compliant OCSP Responders
#1391066 RESOLVED Ca Certificate Compliance Opened 2017-08-16 · Closed 2023-02-22 · 87% similar
SwissSign: Non-BR-Compliant Certificate Issuance
#1391056 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-08-16 · Closed 2023-02-22 · 86% similar
NetLock: Non-BR-Compliant Certificate Issuance
#1544586 RESOLVED Ca Certificate Compliance Opened 2019-04-15 · Closed 2023-02-22 · 86% similar
FNMT: Findings in 2019 Audit Statement, including domain validation methods, CAA, etc.
#1390991 RESOLVED Ca Certificate Compliance Incident Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 86% similar
Disig: Non-BR-Compliant Certificate Issuance
#1368171 RESOLVED Ca Certificate Compliance Incident Opened 2017-05-26 · Closed 2024-06-30 · 85% similar
Firmaprofesional: Non-audited, non-technically-constrained intermediate certificates
#1409766 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Opened 2017-10-18 · Closed 2023-02-22 · 85% similar
Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action