← AC Camerfirma, S.A. cases
Bugzilla #1426233 Ca Certificate Compliance Incident

Camerfirma: Non-BR-Compliant OCSP Responders

RESOLVED FIXED AC Camerfirma, S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns OCSP responder behavior for the InfoCert Organization Validation CA 3 and the Intesa Sanpaolo Organization Validation CA intermediates. The OCSP responders were returning a 404 for a GET request and returning a “good” response for an invalid serial number, which Wayne Thayer cited against CA/Browser Forum Baseline Requirements section 4.9.10 (effective 2013-08-01). Camerfirma stated it had been made aware of the problem and that its technical team corrected the GET-method issue for both subCAs and corrected the “good” response for unissued certificates for the InfoCert subCA. Camerfirma also reported that the Intesa Sanpaolo OCSP service issue was solved on 2017-12-22. After Wayne confirmed the OCSP responders no longer appeared on the crt.sh OCSP responder report, he marked the issue as resolved. Camerfirma added procedural controls including an annual BR self-assessment for the subCAs and daily checks of the crt.sh OCSP responder report, and it described adding a PKI senior expert to manage BR/CA Forum/CCADB self-assessment and communications.

Model: gpt-5.4-nano Generated: 2026-06-13 17:41 UTC Revised: 2026-06-16 18:04 UTC Confidence: 0.84 6 comments
Chronology
  1. Wayne Thayer reported OCSP responder non-compliance against BR 4.9.10 and requested an incident report.
  2. Camerfirma reported that the GET-method issue was fixed for both subCAs and the unissued-certificate “good” response was fixed for the InfoCert subCA.
  3. Camerfirma reported that the Intesa Sanpaolo OCSP service issue was solved.
  4. Wayne confirmed the OCSP responders no longer appeared on the crt.sh report and requested additional incident-report details.
  5. Camerfirma described procedural and technical steps (annual BR self-assessment and daily crt.sh checks) to ensure ongoing compliance.
  6. Wayne marked the issue as resolved.
Thread Activity
  1. Fastly representative — Reported that the OCSP responders returned 404 for GET and “good” for an invalid serial number, cited BR 4.9.10 requirements, and requested an incident report.
  2. AC Camerfirma, S.A. — Said the technical team corrected the GET-method issue for both subCAs and the unissued-certificate “good” response for the InfoCert subCA, and stated Intesa Sanpaolo would be solved by 2017-12-22.
  3. AC Camerfirma, S.A. — Confirmed that the Intesa Sanpaolo OCSP service issue was solved on 2017-12-22.
  4. Fastly representative — Confirmed the responders no longer appeared on crt.sh and asked for more incident-report information about ensuring no other BR failures and ensuring future compliance.
  5. AC Camerfirma, S.A. — Stated they added annual BR self-assessment for the subCAs and daily checks of the crt.sh OCSP responder report, and described adding a PKI senior expert to manage BR/CCADB/self-assessment impacts.
  6. Fastly representative — Marked the issue as resolved.
Participants
Fastly representative AC Camerfirma, S.A.
Similar Local Cases
#1524871 RESOLVED Revocation Issue Incident Opened 2019-02-03 · Closed 2023-02-22 · 95% similar
Camerfirma: failure to revoke underscores
#1532333 RESOLVED Revocation Issue Incident Opened 2019-03-04 · Closed 2023-02-22 · 95% similar
Camerfirma: Unrevocation of MULTICERT SSL Certification Authority 001 certificate
#1575530 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-08-21 · Closed 2023-02-22 · 94% similar
Camerfirma: Govern d'Andorra audits
#1586860 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-10-07 · Closed 2023-02-22 · 94% similar
Camerfirma: Invalid authorityKeyIdentifier, violating Mozilla Policy and RFC 5280
#1672409 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2020-10-21 · Closed 2023-02-22 · 87% similar
Camerfirma: suspicious certificate for com.com
#1509002 RESOLVED Policy Document Issue Incident Opened 2018-11-21 · Closed 2023-02-22 · 87% similar
Camerfirma: MULTICERT certificates with a validity period greater than 825 days
#1686524 RESOLVED Self Reported Incident Incident Opened 2021-01-13 · Closed 2023-02-22 · 86% similar
Camerfirma: Certificate issued with 3-year lifespan, unknown policy
#1672029 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-10-19 · Closed 2023-02-22 · 86% similar
Camerfirma: Failure to abide by Section 8 of Mozilla Policy: Unauthorized, improperly disclosed Subordinate CA

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action