← DarkMatter LLC cases
Bugzilla #1426238
Certificate Misissuance
QuoVadis: Non-BR-Compliant OCSP Responder
RESOLVED
FIXED
DarkMatter LLC
AI Summary
The OCSP responder for the QuoVadis ElDI-V CA G1 intermediate was found to be returning a 'good' response for invalid serial numbers, violating the Baseline Requirements (BRs). This misconfiguration was promptly addressed after it was reported, with the issue resolved within two days. The CA misunderstood its compliance obligations under the BRs, leading to additional checks to ensure no other CAs were similarly non-compliant. External auditors will be notified of the incident.
Chronology
- Issue reported by Rob Stradling
- Issue resolved
Participants
Wayne Thayer
Stephen Davidson
External References
Similar Local Cases
QuoVadis: Certificate containing Debian weak key
QuoVadis: Non-BR-Compliant issuance --improper characters in DNSName (BIT sub-CA)
QuoVadis: Multiple unreported misissuances in 2018
QuoVadis: IPaddress in DNSname SAN
QuoVadis: improper countryName format
Telia: Non-BR-Compliant OCSP Responder
SwissSign: Undisclosed Intermediate Certificates
DocuSign/Keynectis: Undisclosed Intermediate certificate