← Telia Company cases
Bugzilla #1426247
Certificate Misissuance
Telia: Non-BR-Compliant OCSP Responder
RESOLVED
FIXED
Telia Company
AI Summary
The Telia OCSP responder for the TeliaSonera Root CA v1 was found to be returning 'good' responses for unissued certificates, violating the Baseline Requirements (BRs). Telia acknowledged the issue and planned to upgrade their OCSP system to resolve it. Despite a delay in the upgrade, the issue was ultimately fixed, although there were complications during the transition that temporarily affected the accuracy of OCSP responses. A full incident report was provided detailing the timeline and nature of the issues encountered.
Chronology
- Initial report of non-compliance with OCSP responder.
- Planned upgrade to new OCSP system announced.
- Technical problems reported with new OCSP system.
- QA contact changed.
- Confirmation that the problem was fixed.
- Full incident report submitted.
Participants
Wayne Thayer
pekka.lahtiharju@teliasonera.com
External References
Similar Local Cases
Telia: Failure to disclose Unconstrained Intermediate within 7 Days
Telia: Misissued certificate - Invalid OU value "-"
Telia: Misissued certificate - wrong OrganizationName value "Hair 8 Brains"
Telia: Misissued certificate - Invalid wildcard format
Telia: Misissued certificate - FQDN without domain part (e_dnsname_not_valid_tld)
Telia: misissued certificate - FQDN value incorrectly in SAN rfc822 field
Telia: invalid IP value in SAN DNS field
Telia: Ambiguity on KeyUsage with ECC public key