SECOM: Non-BR-Compliant OCSP Responders
This case involves SECOM Trust Systems CO., LTD. disclosing a compliance issue related to their OCSP responders, which were found to be returning 'good' statuses for unissued certificates, violating the Baseline Requirements (BRs). The issue was initially reported in the mozilla.dev.security.policy forum, prompting SECOM to investigate and implement countermeasures. SECOM communicated their progress and actions taken, including revoking SHA-1 OCSP responder certificates and modifying their systems to comply with BR requirements. The issue was resolved, with confirmation that all OCSP responses are now compliant.
- Initial report of non-compliance with OCSP responders
- Confirmation that the issue for intermediate CAs was resolved
- Mozilla representative — Reported problems with OCSP responders for SECOM.
- Secom representative — SECOM began examining details of countermeasures.
- Secom representative — Acknowledged failure to implement countermeasures in a timely manner.
- Secom representative — Informed that the issue for intermediate CAs was solved.
- Fastly representative — Confirmed that the problem has been fixed and marked the case as resolved.