← Google Trust Services LLC cases
Bugzilla #1522975 Ca Security Vulnerability Incident

Google Trust Services: Improper OCSP response for intermediate certificate

RESOLVED FIXED Google Trust Services LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Google Trust Services reported an incident involving an improperly generated OCSP response for its intermediate certificate GTSY1. The issue was identified on January 11, 2019, when a serial number mismatch was discovered during preparations for the certificate's use. Although the incorrect response did not affect any subscribers or relying parties, the CA proactively disclosed the incident and outlined remediation steps. These included generating a correct OCSP response, configuring alerting for newly created subCAs, and improving procedures for generating subCAs. The incident was resolved with the necessary corrections implemented by January 30, 2019.

Model: gpt-4o-mini Generated: 2026-06-13 17:59 UTC Revised: 2026-06-16 18:29 UTC Confidence: 0.90 12 comments
Chronology
  1. Serial number mismatch in OCSP response discovered
  2. Correct OCSP response for GTSY1 published
  3. Additional linters implemented to prevent future errors
Thread Activity
  1. Community commenter — Google Trust Services reported an incident related to OCSP generation.
  2. Google representative — Details about the concerned CA GTSY1 and OCSP Responder URL provided.
  3. Google representative — Confirmed that additional linters were implemented to catch similar errors.
  4. Fastly representative — All questions have been answered and remediation is complete.
Participants
Community commenter Google representative Fastly representative
Similar Local Cases
#1708516 RESOLVED Incident Opened 2021-04-29 · Closed 2023-02-22 · 86% similar
Google Trust Services: Failure to provide regular and timely incident updates
#1793467 RESOLVED Ca Security Vulnerability Opened 2022-10-03 · Closed 2023-02-22 · 83% similar
Google Trust Services: invalid CRL reason code
#1959867 RESOLVED Incident Opened 2025-04-11 · Closed 2025-06-10 · 81% similar
Google Trust Services: Inconsistent MPCAA secondary perspective logging
#1731164 RESOLVED Incident Opened 2021-09-16 · Closed 2023-02-22 · 80% similar
Google Trust Services: CRL validity period set to expected value plus one second
#1758372 RESOLVED Incident Opened 2022-03-07 · Closed 2023-02-22 · 80% similar
Google Trust Services: Incorrect OCSP response for issued certificate
#1773556 RESOLVED Ca Security Vulnerability Opened 2022-06-09 · Closed 2023-02-22 · 80% similar
Google Trust Services: Incorrect OCSP responses for certain certificates
#1931413 RESOLVED Incident Opened 2024-11-14 · Closed 2024-12-27 · 79% similar
Google Trust Services: New hire onboarding deviation from written procedure
#1948368 RESOLVED Incident Opened 2025-02-14 · Closed 2025-03-14 · 78% similar
Google Trust Services: Self-audit tooling MPIC perspective verification inconsistency

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action