← Trustis cases
Bugzilla #1426249 Self Reported Incident

Trustis: Non-Br-Compliant OCSP Responder

RESOLVED FIXED Trustis
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns Trustis's non-compliance with the Baseline Requirements regarding OCSP responses. The issue was identified when it was discovered that OCSP responders were incorrectly returning a 'good' status for invalid serial numbers. Trustis initiated an investigation and confirmed that their software did not support the requirement. They ceased issuing certificates and planned to migrate their OCSP service to a compliant infrastructure. An incident report was provided detailing the timeline of actions taken and confirming that no non-compliant certificates were issued after January 7, 2018. The issue has been resolved, and Trustis is no longer on the list of non-compliant responders.

Model: gpt-4o-mini Generated: 2026-06-13 17:41 UTC Revised: 2026-06-16 18:13 UTC Confidence: 0.90 11 comments
Chronology
  1. Trustis became aware of the OCSP issue through a Bugzilla notice.
  2. Trustis confirmed the need for remediation and planned to migrate OCSP services.
  3. Trustis completed the investigation and remediation of the OCSP issue.
  4. Trustis confirmed that there are no active certificates relying on the old OCSP infrastructure.
Thread Activity
  1. Fastly representative — The OCSP responders for Trustis were returning a good response for an invalid serial number.
  2. Trustis representative — Trustis is investigating the issue and will provide a compliant incident report.
  3. Trustis representative — Trustis found that the current software does not support the requirement and will migrate OCSP services.
  4. Trustis representative — Trustis completed the investigation and compiled an incident report.
  5. Trustis representative — Trustis confirmed that there are no active certificates relying on the old OCSP infrastructure.
Participants
Community commenter
Similar Local Cases
#1623472 RESOLVED Self Reported Incident Opened 2020-03-18 · Closed 2023-02-22 · 79% similar
Trustis: Gap between audit periods
#1532399 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-03-04 · Closed 2023-02-22 · 69% similar
TrustCor: Insufficient Serial Number Entropy
#1752452 RESOLVED Self Reported Incident Opened 2022-01-28 · Closed 2023-02-22 · 69% similar
Certainly: TLS Using ALPN TLS Version and OID
#1455132 RESOLVED Self Reported Incident Opened 2018-04-18 · Closed 2023-02-22 · 68% similar
SwissSign: Undisclosed Intermediate Certificates
#1551362 RESOLVED Self Reported Incident Revocation Issue Opened 2019-05-14 · Closed 2023-02-22 · 68% similar
Sectigo: "Some-State" in stateOrProvinceName
#1622539 RESOLVED Self Reported Incident Opened 2020-03-14 · Closed 2023-02-22 · 68% similar
Microsec: Issuance of 2 IVCP precertificates without givenName, surName, localityName fields
#1551369 RESOLVED Self Reported Incident Certificate Misissuance Opened 2019-05-14 · Closed 2023-02-22 · 68% similar
Kamu SM: "Some-State" in stateOrProvinceName
#1548713 RESOLVED Self Reported Incident Revocation Issue Opened 2019-05-02 · Closed 2023-02-22 · 67% similar
Sectigo: "Default City" in Subject:localityName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action