← Visa cases
Bugzilla #1398261 Self Reported Incident

Visa: Non-BR-Compliant OCSP Responders

RESOLVED FIXED Visa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case addresses compliance issues with Visa's OCSP responders, which were found to be non-compliant with the CA/Browser Forum Baseline Requirements (BRs). The issue was initially reported by Kathleen Wilson, highlighting that OCSP responders must not respond with a 'good' status for unissued certificates. Visa investigated the problem, escalated it to their vendor, and ultimately decided to transition to a new OCSP infrastructure that meets compliance requirements. The issue has been resolved with the successful deployment of a new solution, and Visa has committed to improving their compliance processes moving forward.

Model: gpt-4o-mini Generated: 2026-06-13 17:10 UTC Revised: 2026-06-16 18:13 UTC Confidence: 0.85 18 comments
Chronology
  1. Initial report of non-compliance with OCSP responders
  2. New OCSP solution successfully deployed and validated
Thread Activity
  1. Mozilla representative — Problems have been found with OCSP responders for this CA, and reported in the mozilla.dev.security.policy forum.
  2. Visa — We reached a conclusion that our current vendor is unable to provide us a workable solution.
  3. Visa — The Visa OCSP Service is responding properly to all validation requests.
Participants
Mozilla representative Visa Community commenter
External References
Similar Local Cases
#1315016 RESOLVED Self Reported Incident Opened 2016-11-03 · Closed 2022-11-14 · 100% similar
SHA-1 issuance by Visa root
#1391087 RESOLVED Self Reported Incident Opened 2017-08-16 · Closed 2023-02-22 · 100% similar
Visa: Non-BR-Compliant Certificate Issuance
#1393557 RESOLVED Self Reported Incident Incident Opened 2017-08-24 · Closed 2023-02-22 · 86% similar
GlobalSign: Non-BR-Compliant Certificate Issuance -- RSA key smaller than 2048 bits
#1391056 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-08-16 · Closed 2023-02-22 · 82% similar
NetLock: Non-BR-Compliant Certificate Issuance
#1397969 RESOLVED Self Reported Incident Opened 2017-09-08 · Closed 2023-02-22 · 82% similar
DigiCert / Inteso San Paulo: Double dot characters
#1397960 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-09-07 · Closed 2023-02-22 · 81% similar
DigiCert / Telecom Italia: Several Problems
#1398259 RESOLVED Self Reported Incident Incident Closure Request Opened 2017-09-08 · Closed 2023-02-22 · 80% similar
SECOM: Non-BR-Compliant OCSP Responders
#1390998 RESOLVED Self Reported Incident Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 79% similar
Kamu SM: Non-BR-Compliant Certificate Issuance

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action