QuoVadis: OCSP handling of Certificate Transparency pre-certificates
This case concerns QuoVadis reporting an OCSP handling issue related to Certificate Transparency (CT) pre-certificates when corresponding final certificates are delayed or not issued. QuoVadis stated it had been in discussions with PrimeKey to investigate the issue and indicated it would file an incident report after its investigation. QuoVadis confirmed it had issued 372 “stalled” pre-certs for which corresponding actual certificates with the same serial number were not issued, and that many of these stalled pre-certs did not appear in any CT log. QuoVadis reported that it currently showed OCSP responses of revoked/certificateHold for those stalled pre-certs and was testing a script to change their status to revoked/superceded, expecting production completion during the week of September 16. QuoVadis also reported that PrimeKey targeted an EJBCA feature change (EJBCA 7.3.1 tentatively for November) to make OCSP respond “good” for a pre-cert when it is logged, and that it was looking into improved monitoring and improved OCSP validation in the interim. The bug was later resolved as INVALID by the Mozilla policy reviewer, referencing an outcome from a mozilla.dev.security.policy discussion.
- QuoVadis disclosed an incident report about OCSP handling for CT pre-certificates when final certificates are delayed or not issued.
- QuoVadis confirmed 372 stalled pre-certificates and began testing a script to change their OCSP status to revoked/superceded, targeting production completion the week of September 16.
- Mozilla resolved the incident report as INVALID following a mozilla.dev.security.policy discussion.
- DigiCert — Stephen Davidson (QuoVadis) described related disclosures by other CAs, noted QuoVadis may be impacted as an EJBCA user, and said QuoVadis would file an incident report after investigation.
- Community commenter — Ryan Sleevi asked for a timeline for providing additional details.
- DigiCert — Stephen Davidson said he could not provide a timeframe and outlined three issues, including determining whether stalled pre-certs exist and ensuring OCSP provides a compliant response for pre-certs.
- Community commenter — Ryan Sleevi requested weekly updates per Mozilla policy and suggested GlobalSign’s status as a first concrete deliverable.
- DigiCert — Stephen Davidson confirmed 372 stalled pre-certs, reported current OCSP responses as revoked/certificateHold, and stated testing a script to change them to revoked/superceded with production completion targeted for the week of September 16.
- DigiCert — Stephen Davidson said the bug would progress when more information on the EJBCA feature change became available to support OCSP “good” responses for logged precerts and easier revocation when required.
- Fastly representative — W. Thayer thanked QuoVadis for the incident report and resolved the incident as INVALID, citing the outcome of a mozilla.dev.security.policy discussion.