← Izenpe S.A. cases
Bugzilla #1398258 Ca Certificate Compliance Incident

Izenpe: Non-BR-Compliant OCSP Responders

RESOLVED FIXED Izenpe S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case records an incident involving Izenpe S.A.’s OCSP responders that were found to be non-compliant with the Baseline Requirements. The requirement cited in the bug is that OCSP responders MUST NOT respond with a “good” status for unissued certificates, with an effective date of 2013-08-01. Izenpe stated it became aware of the problem in late August 2017 after it was published in the mozilla.dev.security.policy group, and it then checked OCSP responses for certificates it issues. Izenpe reported that the issue was limited to certificates issued by its ROOT CA, because its OCSP responses for the root CA were built over an ARL and certificates not present in the ARL were assumed to be “good.” Izenpe said it fixed the problem in its development environment and then deployed the fix to production by the end of the day after disclosure, and it described adding test coverage for root CA-related requests. Mozilla asked for the incident report, and the bug was resolved as FIXED, with Gerv indicating the issue could be resolved given it was limited to the root certificate requiring manual responder configuration.

Model: gpt-5.4-nano Generated: 2026-06-13 17:09 UTC Revised: 2026-06-16 19:09 UTC Confidence: 0.86 4 comments
Chronology
  1. Izenpe became aware of an OCSP compliance problem after it was published in the mozilla.dev.security.policy group.
  2. Izenpe fixed the OCSP responder behavior in production.
  3. Mozilla CA Program bug was opened to record Izenpe’s incident report.
  4. Izenpe provided the incident report details, including awareness date, timeline, and remediation/testing steps.
  5. Mozilla indicated the case could be resolved based on the scope of the issue.
Thread Activity
  1. Mozilla representative — Reported that OCSP responders were non-compliant with BR 4.9.10 and requested an incident report, noting the problem was fixed as of 2017-09-05.
  2. Mozilla representative — Asked o-garcia to provide the incident report for the incident.
  3. Izenpe S.A. — Provided the incident report: awareness in August 29th, investigation showing the issue only affected ROOT CA-issued certificates, explanation of ARL-based OCSP behavior, and remediation plus plans to add root CA test cases.
  4. Mozilla representative — Noted the issue was only for the root certificate (manual responder configuration) and that it could be resolved.
Participants
Mozilla representative Izenpe S.A.
Similar Local Cases
#1391054 RESOLVED Ca Certificate Compliance Incident Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 90% similar
Izenpe: Non-BR-Compliant Certificate Issuance
#1559765 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-06-17 · Closed 2023-02-22 · 82% similar
Izenpe: Multiple invalid EV certificates issued
#1651026 RESOLVED Certificate Misissuance Incident Remediation Tracking Opened 2020-07-07 · Closed 2023-02-22 · 81% similar
Izenpe: certificate issued to internal domain
#1398255 RESOLVED Ca Certificate Compliance Incident Opened 2017-09-08 · Closed 2023-02-22 · 76% similar
IdenTrust: Non-BR-Compliant OCSP Responders
#1390997 RESOLVED Ca Certificate Compliance Incident Revocation Issue Opened 2017-08-16 · Closed 2023-02-22 · 72% similar
GlobalSign: Non-BR-Compliant Certificate Issuance - metadata-only subject fields
#1426233 RESOLVED Ca Certificate Compliance Incident Opened 2017-12-19 · Closed 2023-02-22 · 72% similar
Camerfirma: Non-BR-Compliant OCSP Responders
#2009545 RESOLVED Ca Certificate Compliance Incident Repository Issue Opened 2026-01-10 · Closed 2026-02-11 · 71% similar
Microsoft PKI Services: Improper Disclosure of CRLs – Protocol Scheme
#1738778 RESOLVED Ca Certificate Compliance Incident Remediation Tracking Opened 2021-11-01 · Closed 2023-02-22 · 71% similar
TWCA: Policy OID not set to indicate the assurance level to the issued certs

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action