Izenpe: Non-BR-Compliant OCSP Responders
This case records an incident involving Izenpe S.A.’s OCSP responders that were found to be non-compliant with the Baseline Requirements. The requirement cited in the bug is that OCSP responders MUST NOT respond with a “good” status for unissued certificates, with an effective date of 2013-08-01. Izenpe stated it became aware of the problem in late August 2017 after it was published in the mozilla.dev.security.policy group, and it then checked OCSP responses for certificates it issues. Izenpe reported that the issue was limited to certificates issued by its ROOT CA, because its OCSP responses for the root CA were built over an ARL and certificates not present in the ARL were assumed to be “good.” Izenpe said it fixed the problem in its development environment and then deployed the fix to production by the end of the day after disclosure, and it described adding test coverage for root CA-related requests. Mozilla asked for the incident report, and the bug was resolved as FIXED, with Gerv indicating the issue could be resolved given it was limited to the root certificate requiring manual responder configuration.
- Izenpe became aware of an OCSP compliance problem after it was published in the mozilla.dev.security.policy group.
- Izenpe fixed the OCSP responder behavior in production.
- Mozilla CA Program bug was opened to record Izenpe’s incident report.
- Izenpe provided the incident report details, including awareness date, timeline, and remediation/testing steps.
- Mozilla indicated the case could be resolved based on the scope of the issue.
- Mozilla representative — Reported that OCSP responders were non-compliant with BR 4.9.10 and requested an incident report, noting the problem was fixed as of 2017-09-05.
- Mozilla representative — Asked o-garcia to provide the incident report for the incident.
- Izenpe S.A. — Provided the incident report: awareness in August 29th, investigation showing the issue only affected ROOT CA-issued certificates, explanation of ARL-based OCSP behavior, and remediation plus plans to add root CA test cases.
- Mozilla representative — Noted the issue was only for the root certificate (manual responder configuration) and that it could be resolved.