← DigiCert cases
Bugzilla #1523676 Delayed Revocation

DigiCert: OCSP responses returned “good” for revoked intermediates chained to Baltimore CyberTrust Root

RESOLVED FIXED DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The case reports that nine CA certificates chained to the Baltimore CyberTrust Root were revoked via CRL, but the OCSP responder returned “good” responses. The issue was reported to Mozilla by Corey Bonnell via the mozilla.dev.security.policy list, and DigiCert opened an incident report describing the problem. DigiCert stated that it became aware of the problem at about 14:09 MST on January 27, 2019, and began reviewing the affected certificates and their AIA/OCSP responder endpoints. DigiCert then updated the OCSP responder records to mark the certificates as revoked, pushed updated OCSP responses to content distribution networks, and performed a second update to ensure correct revocation dates and times. DigiCert reported that once it was aware of the problem, it corrected it and that OCSP responses were correct within about 4 hours. The bug was later marked as fixed, with a comment indicating remediation was complete and a request to close the bug.

Model: gpt-5.4-nano Generated: 2026-06-13 11:25 UTC Revised: 2026-06-16 18:57 UTC Confidence: 0.84 5 comments
Chronology
  1. DigiCert corrected erroneous OCSP responder data for nine revoked CA certificates chained to the Baltimore CyberTrust Root.
Thread Activity
  1. Fastly representative — Wayne Thayer (posting on behalf of Corey Bonnell) reported that multiple Baltimore CyberTrust Root-chained intermediates were revoked via CRL but the OCSP responder returned “good,” and requested an incident report.
  2. Fastly representative — Wayne Thayer noted that Ben Wilson said the issue had been fixed and linked to a follow-up message.
  3. Community commenter — Ben Wilson provided DigiCert’s incident report, including how DigiCert discovered the erroneous OCSP responses, the timeline of remediation actions, and that OCSP responses were corrected within about 4 hours.
  4. Community commenter — Ben Wilson asked whether the bug could be closed.
  5. Fastly representative — Wayne Thayer replied that remediation appeared to be complete.
Participants
Fastly representative Community commenter
Similar Local Cases
#1442091 RESOLVED Delayed Revocation Opened 2018-03-01 · Closed 2023-02-22 · 96% similar
DigiCert: Unrevocation of BT Class 2 CA - G2 CA Certificate
#1524875 RESOLVED Delayed Revocation Opened 2019-02-03 · Closed 2023-02-22 · 89% similar
DigiCert: IP in dnsName
#1517617 RESOLVED Delayed Revocation Opened 2019-01-03 · Closed 2023-02-22 · 88% similar
DigiCert: Underscores - Citi
#1519572 RESOLVED Delayed Revocation Opened 2019-01-11 · Closed 2023-02-22 · 88% similar
DigiCert: Underscores - Intuit
#1483639 RESOLVED Revocation Issue Delayed Revocation Opened 2018-08-15 · Closed 2024-06-30 · 87% similar
DigiCert / ADACOM: published expired CRLs
#1653475 RESOLVED Delayed Revocation Opened 2020-07-17 · Closed 2023-02-22 · 82% similar
DigiCert: Key Size Not Divisible By 8
#1693343 RESOLVED Delayed Revocation Opened 2021-02-17 · Closed 2023-02-22 · 81% similar
DigiCert: Failure to find and revoke key-compromised certificates within 24 hours
#1797165 RESOLVED Delayed Revocation Opened 2022-10-24 · Closed 2023-02-22 · 81% similar
DigiCert: Delayed Revocation of ~5.5 hours

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action