HARICA: OCSP responder returned "Unauthorized" for some pre-certificates
HARICA reported an incident involving its OCSP responder returning the status "Unauthorized" for some pre-certificates for which no final certificate was issued. The issue was identified through HARICA’s monitoring of m.d.s.p. and related discussions, and HARICA stated it was affected because it uses EJBCA. HARICA said it created a ticket to PrimeKey and worked toward a solution after PrimeKey acknowledged the issue and published an announcement to help customers detect and correct it. HARICA reported that it wrote scripts to scan and correct the problem, applied mitigation early on September 12 (Greek time), and completed its incident report. The incident report was attached to the bug as a PDF. A Mozilla participant later resolved the incident as INVALID, referencing a discussion on the mozilla.dev.security.policy mailing list.
- HARICA reported that its OCSP responder returned "Unauthorized" for some pre-certificates and began working with PrimeKey on mitigation.
- HARICA applied mitigation to address the OCSP responder behavior and completed its Mozilla incident report.
- The incident was resolved as INVALID following discussion on the mozilla.dev.security.policy mailing list.
- HARICA — HARICA described the OCSP "Unauthorized" responses for some pre-certificates, noted PrimeKey’s acknowledgement and public announcement, and said it would provide a full incident report after applying updates.
- HARICA — HARICA apologized for extra spam after cloning another bug copied the CC list.
- Community commenter — Ryan asked for a concrete timeline for when the incident report would be provided.
- HARICA — HARICA stated it expected to test and complete the workaround within 24–48 hours and to prepare the full incident report by September 20.
- Community commenter — Ryan requested clarification on the timing basis and proposed updating the timeline once initial mitigation was confirmed.
- HARICA — HARICA attached the completed incident report and stated it applied mitigation early that day and finished the report.
- Community commenter — Ryan asked whether HARICA’s management discovered and followed earlier discussions about "unknown" statuses referenced in other bugs and a Certinomis issues list.
- HARICA — HARICA responded that it was aware of Certinomis discussions, explained what it initially thought the reference was, and acknowledged it might have missed a specific reference.
- Fastly representative — Wthayer resolved the incident as INVALID, citing the outcome of discussion on the mozilla.dev.security.policy list.