SSL.com: Precertificates without corresponding certificates return OCSP value of "Unknown"
SSL.com reported an OCSP status-reporting issue affecting its precertificates. The problem was discovered during SSL.com’s investigation after reviewing OCSP issues encountered by other CAs (including Let's Encrypt and GlobalSign), and SSL.com found precertificates that did not have corresponding issued certificates and that returned an OCSP status of "Unknown". SSL.com stated that its research indicated the issue was related to EJBCA and opened a ticket with PrimeKey to address the EJBCA problem. SSL.com reported that, after PrimeKey feedback, it imported all affected certificates into its database and its OCSP server no longer returned "Unknown" for the affected items. SSL.com also stated that it applied in-house remediation to resolve remaining issues and that it intended to publish a full incident report in the bug once investigation was complete. A Mozilla participant later resolved the incident as INVALID, referencing a discussion on the mozilla.dev.security.policy mailing list.
- SSL.com discovered and confirmed an OCSP issue where precertificates without corresponding issued certificates returned an OCSP status of "Unknown".
- SSL.com received feedback from PrimeKey and updated its OCSP handling so the OCSP server no longer returned "Unknown" for affected certificates.
- SSL.com continued consultation with PrimeKey and applied further remediation after testing showed not all items returned the expected OCSP status.
- SSL.com applied in-house remediation to resolve remaining issues.
- Mozilla resolved the incident as INVALID following discussion on mozilla.dev.security.policy.
- SSL.com — SSL.com reported that its investigation found precertificates without corresponding issued certificates that returned OCSP status "Unknown" and said it would remediate after PrimeKey provides a fix.
- Community commenter — Ryan asked whether the bug was meant to be the full incident report or whether SSL.com planned further updates, and requested a timeline if more details would be provided.
- SSL.com — SSL.com said it wanted to inform the community early, planned to follow Mozilla best practices, and would submit a preliminary report soon while waiting for PrimeKey feedback.
- SSL.com — SSL.com stated its research was ongoing and that a full report would be published when the investigation was complete.
- SSL.com — SSL.com posted a detailed incident report including how it discovered the issue, the actions taken, and links to crt.sh results for the affected precertificates.
- Fastly representative — Wthayer thanked SSL.com for the incident report and resolved the incident as INVALID, citing the outcome of discussion on mozilla.dev.security.policy.