← DigiCert cases
Bugzilla #1579950 Ca Certificate Compliance Self Reported Incident

QuoVadis: OCSP handling of Certificate Transparency pre-certificates

RESOLVED INVALID DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns QuoVadis reporting an OCSP handling issue related to Certificate Transparency (CT) pre-certificates when corresponding final certificates are delayed or not issued. QuoVadis stated it had been in discussions with PrimeKey to investigate the issue and indicated it would file an incident report after its investigation. QuoVadis confirmed it had issued 372 “stalled” pre-certs for which corresponding actual certificates with the same serial number were not issued, and that many of these stalled pre-certs did not appear in any CT log. QuoVadis reported that it currently showed OCSP responses of revoked/certificateHold for those stalled pre-certs and was testing a script to change their status to revoked/superceded, expecting production completion during the week of September 16. QuoVadis also reported that PrimeKey targeted an EJBCA feature change (EJBCA 7.3.1 tentatively for November) to make OCSP respond “good” for a pre-cert when it is logged, and that it was looking into improved monitoring and improved OCSP validation in the interim. The bug was later resolved as INVALID by the Mozilla policy reviewer, referencing an outcome from a mozilla.dev.security.policy discussion.

Model: gpt-5.4-nano Generated: 2026-06-13 19:35 UTC Revised: 2026-06-16 18:44 UTC Confidence: 0.86 7 comments
Chronology
  1. QuoVadis disclosed an incident report about OCSP handling for CT pre-certificates when final certificates are delayed or not issued.
  2. QuoVadis confirmed 372 stalled pre-certificates and began testing a script to change their OCSP status to revoked/superceded, targeting production completion the week of September 16.
  3. Mozilla resolved the incident report as INVALID following a mozilla.dev.security.policy discussion.
Thread Activity
  1. DigiCert — Stephen Davidson (QuoVadis) described related disclosures by other CAs, noted QuoVadis may be impacted as an EJBCA user, and said QuoVadis would file an incident report after investigation.
  2. Community commenter — Ryan Sleevi asked for a timeline for providing additional details.
  3. DigiCert — Stephen Davidson said he could not provide a timeframe and outlined three issues, including determining whether stalled pre-certs exist and ensuring OCSP provides a compliant response for pre-certs.
  4. Community commenter — Ryan Sleevi requested weekly updates per Mozilla policy and suggested GlobalSign’s status as a first concrete deliverable.
  5. DigiCert — Stephen Davidson confirmed 372 stalled pre-certs, reported current OCSP responses as revoked/certificateHold, and stated testing a script to change them to revoked/superceded with production completion targeted for the week of September 16.
  6. DigiCert — Stephen Davidson said the bug would progress when more information on the EJBCA feature change became available to support OCSP “good” responses for logged precerts and easier revocation when required.
  7. Fastly representative — W. Thayer thanked QuoVadis for the incident report and resolved the incident as INVALID, citing the outcome of a mozilla.dev.security.policy discussion.
Participants
DigiCert Community commenter Fastly representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1581234 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-09-13 · Closed 2023-02-22 · 100% similar
QuoVadis: EV JOI Issue
#1624504 RESOLVED Self Reported Incident Opened 2020-03-24 · Closed 2023-02-22 · 95% similar
QuoVadis: Failure to revoke certificates with compromised private keys
#1738472 RESOLVED Self Reported Incident Opened 2021-10-29 · Closed 2023-02-22 · 87% similar
QuoVadis: hostnames not in preferred name syntax
#1649938 RESOLVED Self Reported Incident Opened 2020-07-02 · Closed 2023-02-22 · 86% similar
QuoVadis: Incorrect OCSP Delegated Responder Certificate
#1538638 RESOLVED Ca Certificate Compliance Self Reported Incident Revocation Issue Opened 2019-03-25 · Closed 2023-02-22 · 86% similar
Firmaprofesional: AC Firmaprofesional - INFRAESTRUCTURA insufficient serial number entropy
#1409766 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Opened 2017-10-18 · Closed 2023-02-22 · 86% similar
Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record
#1525710 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-02-06 · Closed 2023-02-22 · 86% similar
Amazon Trust Services: Test revoked certificates with invalid validity period
#1586860 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-10-07 · Closed 2023-02-22 · 86% similar
Camerfirma: Invalid authorityKeyIdentifier, violating Mozilla Policy and RFC 5280

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action