DocuSign/Keynectis: Non-BR-Compliant OCSP Responders
This case involves DocuSign (Keynectis) disclosing a compliance issue regarding their OCSP responders, which were found to be non-compliant with the Baseline Requirements (BRs). The issue was initially reported in the mozilla.dev.security.policy forum, highlighting that OCSP responders must not respond with a 'good' status for unissued certificates. The CA acknowledged the problem and provided a timeline for remediation, including updates to their OCSP responder configuration. The OCSP responder has since been updated to comply with BR requirements, and an incident report detailing the timeline and corrective actions has been submitted.
- Initial report of non-compliance with OCSP responders
- OCSP responder updated to be BR-compliant
- Incident report submitted detailing the compliance issue and remediation steps
- New audit for the Certplus Class 2 Primary CA received and processed
- Mozilla representative — Problems have been found with OCSP responders for this CA, and reported in the mozilla.dev.security.policy forum.
- Docusign representative — This intermediate CA is offline and used for the Adobe AATL program.
- Docusign representative — The OCSP responder has been updated to be BR-compliant.
- Docusign representative — Here's the incident report detailing the timeline and steps taken.
- Fastly representative — A new audit for the Certplus Class 2 Primary CA has been received and processed.