GlobalSign: OCSP responder returns invalid values for some precertificates
GlobalSign reported an issue affecting OCSP responses for some precertificates that do not have corresponding certificates. The reporter said that, based on announcements by DigiCert and Let’s Encrypt, GlobalSign found that its precertificates without corresponding certificates return Unauthorized or Unknown. GlobalSign stated it was working with PrimeKey on a patch and updating its OCSP services to return proper values. GlobalSign also explained that Mozilla’s requirement is that certificates must not include cRLDistributionPoints or OCSP authorityInfoAccess extensions unless operational CRL or OCSP services exist, and that precertificates are treated as certificates for this purpose. In a later status update, GlobalSign said PrimeKey opened a ticket to resolve the issue in the November time frame in EJBCA 7.3.1, and that GlobalSign opened tickets for its OCSP service to store precertificates in its main certificate database so they are treated the same as certificates for OCSP handling. The incident was ultimately resolved as INVALID by the Mozilla participant, referencing a discussion on the mozilla.dev.security.policy mailing list.
- GlobalSign identified that OCSP responses for some precertificates without corresponding certificates returned Unauthorized or Unknown and initiated remediation work with PrimeKey and its OCSP services.
- GlobalSign reported ongoing remediation steps, including a PrimeKey ticket for an EJBCA fix and OCSP service changes to store precertificates for proper OCSP responses.
- Mozilla resolved the incident report as INVALID after discussion on the mozilla.dev.security.policy mailing list.
- Community commenter — Doug reported that GlobalSign precertificates without corresponding certificates return Unauthorized or Unknown via OCSP and said GlobalSign was working with PrimeKey on a patch and updating its OCSP services.
- Community commenter — Ryan asked whether the report was meant to be the full incident report and requested a timeline for further updates if more details were planned.
- Community commenter — Doug said GlobalSign would provide regular updates and complete an incident report, and explained the core problem as Mozilla’s requirement for operational CRL/OCSP services for extensions present on precertificates.
- Community commenter — Ryan requested weekly updates and a complete remediation timeline.
- Community commenter — Doug provided a status update: PrimeKey opened a ticket for an EJBCA 7.3.1 fix in November, and GlobalSign opened tickets to modify its OCSP service to store precertificates in the main certificate database for proper OCSP responses.
- Fastly representative — Wthayer thanked for the incident report and resolved the incident as INVALID, citing the outcome of discussion on the mozilla.dev.security.policy list.