Telia: Non-BR-Compliant OCSP Responder
The bug reports that the OCSP responder for the TeliaSonera Root CA v1 returned a “good” response for an invalid (unissued) serial number, which Mozilla’s Baseline Requirements state must not happen. The requirement referenced was from BR section 4.9.10, effective 2013-08-01. Telia investigated and acknowledged an OCSP compliance issue: they stated that their SSL certificates were compliant but that sub-CAs were not. Telia planned to move to a completely new OCSP system on 27 Jan 2018, later noting a one-week delay and targeting 3 Feb 2018. After the OCSP system change, Telia reported additional technical problems where some OCSP responses were incorrect for several days due to an incomplete OCSP database after migration, and they temporarily configured the system to return “good” instead of “unknown” to avoid breaking customer certificate use. Telia later confirmed the problem was fixed and provided a full incident report, with the second issue fully fixed by 9 Feb 2018 and the normal OCSP response configuration restored immediately afterward.
- A report was filed alleging TeliaSonera Root CA v1 OCSP returned “good” for unissued certificate serial numbers.
- Telia planned an OCSP system upgrade to address the non-compliant OCSP behavior.
- Telia completed the OCSP system update, after which additional OCSP response issues were observed for a period.
- Telia reported the OCSP response issues were fully fixed and normal configuration restored.
- Telia confirmed the problem was fixed and provided follow-up incident-report information.
- Telia posted a full incident report covering both OCSP-related issues.
- Fastly representative — Reported that TeliaSonera Root CA v1 OCSP returned “good” for an invalid serial number and requested an incident report per Mozilla guidance.
- Teliasonera representative — Admitted an issue with Telia Root CA OCSP, stated the BR requirement applied to CA certificates, and described a plan to move to a new OCSP system on 27 Jan 2018.
- Teliasonera representative — Noted a one-week delay and that the issue would be solved on 3 Feb 2018.
- Fastly representative — Asked for a status update because crt.sh still showed non-compliant Telia OCSP responders.
- Teliasonera representative — Said the OCSP system was changed and that technical problems occurred; described incomplete OCSP databases and a temporary configuration to return “good” instead of “unknown,” with plans to revert after the week.
- Mozilla representative — Changed the QA contact per a referenced Bugzilla change.
- Fastly representative — Confirmed the problem was fixed and requested the complete incident report.
- Teliasonera representative — Provided a full incident report describing two OCSP-related issues, their timing, causes, and remediation (including database recovery and restoring normal configuration).