← Telia Company cases
Bugzilla #1426247 Revocation Issue

Telia: Non-BR-Compliant OCSP Responder

RESOLVED FIXED Telia Company
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The bug reports that the OCSP responder for the TeliaSonera Root CA v1 returned a “good” response for an invalid (unissued) serial number, which Mozilla’s Baseline Requirements state must not happen. The requirement referenced was from BR section 4.9.10, effective 2013-08-01. Telia investigated and acknowledged an OCSP compliance issue: they stated that their SSL certificates were compliant but that sub-CAs were not. Telia planned to move to a completely new OCSP system on 27 Jan 2018, later noting a one-week delay and targeting 3 Feb 2018. After the OCSP system change, Telia reported additional technical problems where some OCSP responses were incorrect for several days due to an incomplete OCSP database after migration, and they temporarily configured the system to return “good” instead of “unknown” to avoid breaking customer certificate use. Telia later confirmed the problem was fixed and provided a full incident report, with the second issue fully fixed by 9 Feb 2018 and the normal OCSP response configuration restored immediately afterward.

Model: gpt-5.4-nano Generated: 2026-06-13 17:41 UTC Revised: 2026-06-16 18:11 UTC Confidence: 0.50 8 comments
Chronology
  1. A report was filed alleging TeliaSonera Root CA v1 OCSP returned “good” for unissued certificate serial numbers.
  2. Telia planned an OCSP system upgrade to address the non-compliant OCSP behavior.
  3. Telia completed the OCSP system update, after which additional OCSP response issues were observed for a period.
  4. Telia reported the OCSP response issues were fully fixed and normal configuration restored.
  5. Telia confirmed the problem was fixed and provided follow-up incident-report information.
  6. Telia posted a full incident report covering both OCSP-related issues.
Thread Activity
  1. Fastly representative — Reported that TeliaSonera Root CA v1 OCSP returned “good” for an invalid serial number and requested an incident report per Mozilla guidance.
  2. Teliasonera representative — Admitted an issue with Telia Root CA OCSP, stated the BR requirement applied to CA certificates, and described a plan to move to a new OCSP system on 27 Jan 2018.
  3. Teliasonera representative — Noted a one-week delay and that the issue would be solved on 3 Feb 2018.
  4. Fastly representative — Asked for a status update because crt.sh still showed non-compliant Telia OCSP responders.
  5. Teliasonera representative — Said the OCSP system was changed and that technical problems occurred; described incomplete OCSP databases and a temporary configuration to return “good” instead of “unknown,” with plans to revert after the week.
  6. Mozilla representative — Changed the QA contact per a referenced Bugzilla change.
  7. Fastly representative — Confirmed the problem was fixed and requested the complete incident report.
  8. Teliasonera representative — Provided a full incident report describing two OCSP-related issues, their timing, causes, and remediation (including database recovery and restoring normal configuration).
Participants
Fastly representative Teliasonera representative Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1523680 RESOLVED Revocation Issue Incident Opened 2019-01-29 · Closed 2023-02-22 · 72% similar
Actalis: Non BR Compliant OCSP Responder
#1536831 RESOLVED Ca Certificate Compliance Revocation Issue Remediation Tracking Opened 2019-03-20 · Closed 2023-02-22 · 69% similar
GDCA: Insufficient Serial Number Entropy
#1483639 RESOLVED Revocation Issue Delayed Revocation Opened 2018-08-15 · Closed 2024-06-30 · 66% similar
DigiCert / ADACOM: published expired CRLs
#1391000 RESOLVED Ca Certificate Compliance Incident Revocation Issue Opened 2017-08-16 · Closed 2023-02-22 · 61% similar
IdenTrust: Non-BR-Compliant Certificate Issuance
#1754593 RESOLVED Revocation Issue Opened 2022-02-09 · Closed 2023-02-22 · 61% similar
IdenTrust: Unavailable CRL and OCSP Responders
#1397830 RESOLVED Certificate Misissuance Revocation Issue Opened 2017-09-07 · Closed 2023-02-22 · 60% similar
EDICOM: Signing SHA-1 OCSP responses with unconstrained certificate
#1639804 RESOLVED Revocation Issue Delayed Revocation Opened 2020-05-21 · Closed 2023-02-22 · 59% similar
Sectigo: Failure to revoke key-compromised certificate within 24 hours
#1634795 RESOLVED Revocation Issue Delayed Revocation Opened 2020-05-01 · Closed 2023-02-22 · 59% similar
Google Trust Services: Incorrect revocation data temporarily served for GTS Y3 & Y4

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action