← Entrust cases
Bugzilla #1428891
Technical Compliance
Entrust: Non-BR-Compliant OCSP Responder
RESOLVED
FIXED
Entrust
AI Summary
Entrust faced an issue with its OCSP responders returning a 'good' status for invalid serial numbers, violating the Baseline Requirements (BRs). The problem was identified on January 8, 2018, and Entrust initiated a corrective action plan. By January 26, 2018, the OCSP system was updated to ensure compliance, and it was confirmed that the issue was resolved. No problematic certificates were issued during this period, and the CAs involved are subject to annual audits.
Chronology
- Bug reported regarding OCSP responder compliance.
- Entrust provided details on the issue and corrective actions.
- Entrust confirmed OCSP system correction.
- Compliance confirmed; bug resolved.
Participants
Wayne Thayer
Bruce Morton
Gervase Markham
Ryan Sleevi
External References
Similar Local Cases
Consorci AOC: Non-BR-Compliant OCSP Responders
Visa: Non-BR-Compliant OCSP Responders
DocuSign/Keynectis: Non-Compliant Technically Constrained Intermediates
startcom: still issuing < 2048 bit certificates
DigiCert: SCEE / Justica: Non-BR-Compliant Certificate Issuance
Firmaprofesional: Non-BR-Compliant OCSP Responders
Amazon Trust Services: CRL not DER-encoded
Amazon Trust Services: Missing CAA Check For Test Website Certificates