← Trustis cases
Bugzilla #1426249
Certificate Problem Report
Trustis: Non-Br-Compliant OCSP Responder
RESOLVED
FIXED
Trustis
AI Summary
The Trustis OCSP responders were found to be returning a 'good' status for invalid serial numbers, violating the Baseline Requirements (BR) effective since August 2013. Trustis acknowledged the issue and confirmed that they ceased issuing certificates on January 7, 2018, while working on a compliant OCSP solution. An incident report was provided detailing the timeline of actions taken to resolve the issue, including the migration of OCSP services to Entrust Datacard infrastructure. The case has been resolved with confirmation that no problematic certificates were issued.
Chronology
- Bug reported regarding non-compliance of OCSP responder.
- Trustis stopped issuing certificates.
- OCSP fix tested and confirmed as completed.
- Trustis confirmed no active certificates rely on the old OCSP infrastructure.
Participants
Wayne Thayer
Blake Morgan
External References
Similar Local Cases
DocuSign/Keynectis: Non-BR-Compliant OCSP Responders
Actalis: Non BR Compliant OCSP Responder
DigiCert: Verizon: "Default City" in Subject:localityName
SECOM: Non-BR-Compliant OCSP Responders
DigiCert: Non-BR-Compliant OCSP Responders
QuoVadis: DarkMatter Insufficient Serial Number Entropy
SECOM: failure to revoke underscores
DigiCert: Apple: Precertificates without corresponding certificates return OCSP value of "unknown"