Consorci AOC: OCSP responses good for non-issued certs (duplicate of bug 1398246)
This case concerns an OCSP behavior where responses were “good” for non-issued certificates under the Consorci AOC root. The issue was reported by Wayne Thayer, referencing bug 1398246#c24, and the expected behavior was that such certificates should have been “unknown” rather than “good.” Consorci AOC stated that it was not an issuance problem and not a security issue, and that its monitoring system detected the problem at 1:30 AM on June 1. The CA reported that its SysOp started work at 6:00 AM CET on June 1 and that the issue was solved at 8:00 AM CET. The CA attributed the problem to synchronization between a master and slave database after adding a redundant SAN, and it described that the service was configured to fall back to reading certificate status from the CRL if OCSP became slow or stopped. The bug was ultimately marked as a duplicate of bug 1398246.
- Consorci AOC detected an OCSP issue where responses were good for non-issued certificates and resolved it the same morning.
- Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert) — Reported that OCSP responses were good for non-issued certificates and stated the expected outcome was “unknown,” noting monitoring detection at 1:30 AM June 1 and resolution at 8:00 AM CET.
- Mozilla representative — Set the component to match the origin issue based on bug 1398246#c24.
- Fastly representative — Marked this bug as a duplicate of bug 1398246.