DigiCert OCSP responders returned 'good' for unissued certificates and were remediated
This case concerns reports that DigiCert-related OCSP responders were returning a "good" status for unissued certificates, which Mozilla noted was non-compliant with BR section 4.9.10. The issue was first raised by Kathleen Wilson after problems were found and discussed in the mozilla.dev.security.policy forum. DigiCert responded with incident details for several affected entities, including ABB, Intesa Sanpaolo, Multicert/SCEE, and Wells Fargo, and discussed remediation steps such as patching responders, adding some certificates to OneCRL, and moving OCSP infrastructure. The thread also covered a separate OCSP issue for the Baltimore CyberTrust Root, which was later confirmed to be a false positive for one reported error but still had a responder returning "good" for an unknown serial number. By June 2018, DigiCert reported that migration of http://ocsp.omniroot.com/baltimoreroot and DNS had been completed and that the server now returned "unauthorized" for unissued certificates, after which the issue was confirmed fixed.
- Mozilla reported that DigiCert OCSP responders were returning 'good' for unissued certificates.
- DigiCert provided incident details for ABB's OCSP responder issue and described planned remediation.
- DigiCert said SCEE and Multicert had patched their systems and Intesa Sanpaolo was still working on a fix.
- DigiCert completed migration of the Baltimore CyberTrust Root OCSP responder and it began returning 'unauthorized' for unissued certificates.
- Mozilla representative — Kathleen Wilson opened the bug after reporting that OCSP responders were returning 'good' for unissued certificates and requested an incident report.
- DigiCert — Jeremy Rowley said DigiCert was working with the affected sub-CAs, planned to add SCEE certificates to OneCRL, and was investigating Intesa.
- Community commenter — Ben Wilson posted ABB's incident report, explaining ABB believed its constraints were complete and that the OCSP behavior matched its operating model.
- Community commenter — Ben Wilson said the issues were still being worked on and gave April 30 as the expected timeframe.
- Community commenter — Ben Wilson reported the migration and DNS changes were complete and that the responder now returned 'unauthorized' for unissued certificates.
- Fastly representative — Wayne Thayer confirmed that the issue had been fixed.