Visa: Non-BR-Compliant OCSP Responders
This case addresses compliance issues with Visa's OCSP responders, which were found to be non-compliant with the CA/Browser Forum Baseline Requirements (BRs). The issue was initially reported by Kathleen Wilson, highlighting that OCSP responders must not respond with a 'good' status for unissued certificates. Visa investigated the problem, escalated it to their vendor, and ultimately decided to transition to a new OCSP infrastructure that meets compliance requirements. The issue has been resolved with the successful deployment of a new solution, and Visa has committed to improving their compliance processes moving forward.
- Initial report of non-compliance with OCSP responders
- New OCSP solution successfully deployed and validated
- Mozilla representative — Problems have been found with OCSP responders for this CA, and reported in the mozilla.dev.security.policy forum.
- Visa — We reached a conclusion that our current vendor is unable to provide us a workable solution.
- Visa — The Visa OCSP Service is responding properly to all validation requests.