Entrust: Non-BR-Compliant OCSP Responder
This case concerns Entrust OCSP responders for the Entrust Class 1 Client CA and Entrust Class 2 Client CA intermediates returning a “good” response for an invalid serial number, which Wayne Thayer reported as non-compliant with the Baseline Requirements. Thayer cited BR section 4.9.10, stating OCSP responders must not respond with “good” for unissued certificates (effective 2013-08-01), and asked Entrust to provide an incident report or revoke non-constrained certificates. Entrust said it became aware of the problem via the Bugzilla report email and provided a response plan, stating it would update the OCSP responders to only return “good” for known, non-revoked serial numbers. Entrust also stated that it was not issuing TLS/SSL certificates with the problem and that there were no problematic certificates issued, while later clarifying that the Class 1 and Class 2 CAs had issued S/MIME certificates pointing to these responders (and 0 TLS/SSL certificates). Entrust reported that the OCSP system was corrected on 2018-01-25. Mozilla confirmed the OCSP responders were no longer reported as non-compliant by crt.sh and the bug was resolved as FIXED.
- Wayne Thayer reported that Entrust OCSP responders returned “good” for invalid serial numbers, citing BR 4.9.10.
- Entrust corrected the OCSP system so it would no longer return “good” for invalid/unissued serial numbers.
- Mozilla/Wayne confirmed the OCSP responders were no longer reported as non-compliant and the bug was resolved.
- Fastly representative — Reported that Entrust OCSP responders returned “good” for an invalid serial number and requested an incident report or remediation per BR 4.9.10.
- Entrust representative — Described how Entrust learned of the issue and stated it planned to update OCSP responders to only return “good” for known, non-revoked serial numbers.
- Mozilla representative — Suggested that unconstrained certs either need disclosure/audit as SSL intermediates or be added to OneCRL as an option for legacy certificates.
- Entrust representative — Stated the CAs are disclosed in CCADB, annually audited to WebTrust for CA, and configured not to issue SSL certificates.
- Community commenter — Asked for clarification on whether certificates point to the OCSP responders and noted the effect of OCSP non-compliance on issued certificates.
- Entrust representative — Clarified that Class 1 and Class 2 CAs issued S/MIME certificates pointing to the responders (23259 from 2016-02-01 to 2017-11-30) and 0 TLS/SSL certificates.
- Entrust representative — Reported that the OCSP system was corrected.
- Fastly representative — Confirmed crt.sh no longer reported the OCSP responders as non-compliant and resolved the bug.