DigiCert: OCSP responses returned “good” for revoked intermediates chained to Baltimore CyberTrust Root
The case reports that nine CA certificates chained to the Baltimore CyberTrust Root were revoked via CRL, but the OCSP responder returned “good” responses. The issue was reported to Mozilla by Corey Bonnell via the mozilla.dev.security.policy list, and DigiCert opened an incident report describing the problem. DigiCert stated that it became aware of the problem at about 14:09 MST on January 27, 2019, and began reviewing the affected certificates and their AIA/OCSP responder endpoints. DigiCert then updated the OCSP responder records to mark the certificates as revoked, pushed updated OCSP responses to content distribution networks, and performed a second update to ensure correct revocation dates and times. DigiCert reported that once it was aware of the problem, it corrected it and that OCSP responses were correct within about 4 hours. The bug was later marked as fixed, with a comment indicating remediation was complete and a request to close the bug.
- DigiCert corrected erroneous OCSP responder data for nine revoked CA certificates chained to the Baltimore CyberTrust Root.
- Fastly representative — Wayne Thayer (posting on behalf of Corey Bonnell) reported that multiple Baltimore CyberTrust Root-chained intermediates were revoked via CRL but the OCSP responder returned “good,” and requested an incident report.
- Fastly representative — Wayne Thayer noted that Ben Wilson said the issue had been fixed and linked to a follow-up message.
- Community commenter — Ben Wilson provided DigiCert’s incident report, including how DigiCert discovered the erroneous OCSP responses, the timeline of remediation actions, and that OCSP responses were corrected within about 4 hours.
- Community commenter — Ben Wilson asked whether the bug could be closed.
- Fastly representative — Wayne Thayer replied that remediation appeared to be complete.