← IdenTrust Services, LLC cases
Bugzilla #1398255 Ca Certificate Compliance Incident

IdenTrust: Non-BR-Compliant OCSP Responders

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns IdenTrust OCSP responder behavior that was reported as non-compliant with Mozilla Baseline Requirements. The requirement cited was BR 4.9.10, which states OCSP responders MUST NOT respond with a “good” status for unissued certificates, with an effective date of 2013-08-01. The issue was raised in the mozilla.dev.security.policy forum, and the bug was used to record IdenTrust’s incident report. IdenTrust stated it was notified on August 29, 2017, reviewed the reported violation for DST ACES CA X6, verified the behavior, and formulated and executed a remediation plan. IdenTrust reported that it completed remediation on August 30, 2017 and stopped sending OCSP responses in violation of BR 4.9.10 as of August 30, 2017. IdenTrust also stated the non-compliant AIA OCSP URL was only present in the subordinate CA (IdenTrust ACES CA 1) certificate and was inadvertently missed during an OCPS update activity in 2013, and that the OCSP software accessible at that AIA OCSP URL was permanently deprecated. The bug was resolved as FIXED, and Gerv indicated that since the PKI was now obsolete there was nothing left to do in the bug.

Model: gpt-5.4-nano Generated: 2026-06-13 17:09 UTC Revised: 2026-06-16 19:12 UTC Confidence: 0.86 8 comments
Chronology
  1. IdenTrust was notified of a reported BR 4.9.10 violation for an OCSP responder configuration and began reviewing and verifying the issue for DST ACES CA X6.
  2. IdenTrust completed remediation and stopped sending OCSP responses in violation of BR 4.9.10 for the identified CA certificate.
  3. Mozilla CA Program bug was opened to record IdenTrust’s incident report for the OCSP responder non-compliance.
  4. Mozilla indicated the PKI was obsolete and there was nothing left to do in the bug.
Thread Activity
  1. Community commenter — Requested an incident report in the bug, citing BR 4.9.10 and noting the problem was fixed as of 2017-08-31.
  2. Community commenter — Asked Vishvas to provide the incident report for the incident.
  3. Community commenter — Provided an incident report including notification date (Aug 29, 2017), remediation timeline, confirmation that non-compliant OCSP responses stopped as of Aug 30, 2017, and details about the problematic certificate and cause.
  4. Community commenter — Asked how the non-compliant OCSP URL was missed and questioned why it was not discovered earlier.
  5. Community commenter — Requested an update after the bug had been waiting for two months.
  6. Community commenter — Explained that a PKI roll over occurred during the period and that the non-compliant OCSP URL was only present in the subordinate CA AIA; stated the PKI expired with DST Root CA X6 expiration on Nov 20.
  7. Community commenter — Stated he was not impressed by the records but that since the PKI was obsolete there was nothing left to do in the bug.
Participants
Community commenter
Related Bugzilla IDs Mentioned
Similar Local Cases
#1853783 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2023-09-18 · Closed 2025-03-20 · 82% similar
IdenTrust: S/MIME certificates issued in violation of New S/MIME Baseline Requirements v1.0
#1905446 RESOLVED Incident Opened 2024-06-28 · Closed 2024-12-09 · 81% similar
IdenTrust: Unauthorized OCSP response on a Timestamp certificate
#1391000 RESOLVED Ca Certificate Compliance Incident Revocation Issue Opened 2017-08-16 · Closed 2023-02-22 · 81% similar
IdenTrust: Non-BR-Compliant Certificate Issuance
#1861783 RESOLVED Ca Certificate Compliance Opened 2023-10-28 · Closed 2024-01-04 · 80% similar
IdenTrust: S/MIME Certificates issued without CAB Forum OID
#1900492 RESOLVED Incident Opened 2024-06-03 · Closed 2026-06-10 · 80% similar
IdenTrust: Invalid OrganizationIdentifier in S/MIME certificates
#2025595 RESOLVED Self Reported Incident Incident Opened 2026-03-23 · Closed 2026-05-18 · 80% similar
IdenTrust: Delay in updating a Bug 2014609 - Next update
#2025596 RESOLVED Self Reported Incident Incident Opened 2026-03-23 · Closed 2026-05-18 · 80% similar
IdenTrust: Delay in updating a Bugzilla ticket Bug 2014610 - Next update
#1542082 RESOLVED Incident Self Reported Incident Opened 2019-04-04 · Closed 2023-02-22 · 80% similar
IdenTrust: Failure to disclose Unconstrained intermediate Within 7 Days

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action