← HARICA cases
Bugzilla #1580393 Incident Self Reported Incident

HARICA: OCSP responder returned "Unauthorized" for some pre-certificates

RESOLVED INVALID HARICA
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

HARICA reported an incident involving its OCSP responder returning the status "Unauthorized" for some pre-certificates for which no final certificate was issued. The issue was identified through HARICA’s monitoring of m.d.s.p. and related discussions, and HARICA stated it was affected because it uses EJBCA. HARICA said it created a ticket to PrimeKey and worked toward a solution after PrimeKey acknowledged the issue and published an announcement to help customers detect and correct it. HARICA reported that it wrote scripts to scan and correct the problem, applied mitigation early on September 12 (Greek time), and completed its incident report. The incident report was attached to the bug as a PDF. A Mozilla participant later resolved the incident as INVALID, referencing a discussion on the mozilla.dev.security.policy mailing list.

Model: gpt-5.4-nano Generated: 2026-06-13 19:35 UTC Revised: 2026-06-16 19:11 UTC Confidence: 0.86 9 comments
Chronology
  1. HARICA reported that its OCSP responder returned "Unauthorized" for some pre-certificates and began working with PrimeKey on mitigation.
  2. HARICA applied mitigation to address the OCSP responder behavior and completed its Mozilla incident report.
  3. The incident was resolved as INVALID following discussion on the mozilla.dev.security.policy mailing list.
Thread Activity
  1. HARICA — HARICA described the OCSP "Unauthorized" responses for some pre-certificates, noted PrimeKey’s acknowledgement and public announcement, and said it would provide a full incident report after applying updates.
  2. HARICA — HARICA apologized for extra spam after cloning another bug copied the CC list.
  3. Community commenter — Ryan asked for a concrete timeline for when the incident report would be provided.
  4. HARICA — HARICA stated it expected to test and complete the workaround within 24–48 hours and to prepare the full incident report by September 20.
  5. Community commenter — Ryan requested clarification on the timing basis and proposed updating the timeline once initial mitigation was confirmed.
  6. HARICA — HARICA attached the completed incident report and stated it applied mitigation early that day and finished the report.
  7. Community commenter — Ryan asked whether HARICA’s management discovered and followed earlier discussions about "unknown" statuses referenced in other bugs and a Certinomis issues list.
  8. HARICA — HARICA responded that it was aware of Certinomis discussions, explained what it initially thought the reference was, and acknowledged it might have missed a specific reference.
  9. Fastly representative — Wthayer resolved the incident as INVALID, citing the outcome of discussion on the mozilla.dev.security.policy list.
Participants
HARICA Community commenter Fastly representative
Similar Local Cases
#1700809 RESOLVED Self Reported Incident Incident Opened 2021-03-25 · Closed 2023-02-22 · 84% similar
Microsoft PKI Services: Failure to disclose Unconstrained Intermediate within 7 Days
#1535509 RESOLVED Incident Certificate Misissuance Revocation Issue Opened 2019-03-15 · Closed 2023-02-22 · 82% similar
HARICA: Insufficient serial number entropy
#1699796 RESOLVED Self Reported Incident Certificate Misissuance Opened 2021-03-19 · Closed 2023-02-22 · 82% similar
HARICA: Certificates with invalid policy tree
#1530971 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-02-27 · Closed 2023-02-22 · 81% similar
HARICA: P-384,ecdsa-with-SHA256 Certificates
#2056668 UNCONFIRMED Policy Document Issue Incident Self Reported Incident Certificate Misissuance Opened 2026-07-21 Still Open · 80% similar
HARICA: Issuance of Server TLS Certificates without AIA OCSP URI against CP/CPS
#1535772 RESOLVED Incident Certificate Misissuance Revocation Issue Opened 2019-03-15 · Closed 2023-02-22 · 80% similar
HARICA: wrong characters in NC extension of Technically Constrained Intermediate CA Certificates
#1649945 RESOLVED Self Reported Incident Opened 2020-07-02 · Closed 2023-02-22 · 80% similar
HARICA: Incorrect OCSP Delegated Responder Certificate
#2029643 RESOLVED Self Reported Incident Revocation Issue Certificate Misissuance Opened 2026-04-06 · Closed 2026-05-22 · 80% similar
HARICA: Incorrect Open MPIC Lambda implementation by EJBCA ACME Service

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action