← Visa cases
Bugzilla #1398261
Technical Compliance
Visa: Non-BR-Compliant OCSP Responders
RESOLVED
FIXED
Visa
AI Summary
Visa faced issues with its OCSP responders not complying with the Baseline Requirements (BRs), specifically regarding the requirement that OCSP responders must not return a 'good' status for unissued certificates. After extensive testing, Visa confirmed the issue and escalated it to their vendor for remediation. They ultimately decided to transition to a new OCSP infrastructure that meets Mozilla's requirements. The issue has since been resolved with the successful deployment of a new solution that properly responds to validation requests.
Chronology
- Initial report of OCSP compliance issues.
- New OCSP solution successfully deployed and validated.
Participants
Kathleen Wilson
Marcelo B. Silva
Gervase Markham
Paul Kehrer
Adam Clark
Jason Crawford
Ryan Sleevi
External References
Similar Local Cases
Consorci AOC: Non-BR-Compliant OCSP Responders
Entrust: Non-BR-Compliant OCSP Responder
Firmaprofesional: Non-BR-Compliant OCSP Responders
startcom: still issuing < 2048 bit certificates
Asseco DS / Certum: non-audited intermediate certificate
Visa: Non-BR-Compliant Certificate Issuance
DigiCert: SCEE / Justica: Non-BR-Compliant Certificate Issuance
SwissSign: recommendation on backup testing