← Apple Inc. cases
Bugzilla #1588001 Self Reported Incident

Apple: OCSP responders return responses with incorrect issuer

RESOLVED FIXED Apple Inc.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Apple CA reported an incident where their OCSP responders were returning signed responses with incorrect issuers. The issue was identified on October 3, 2019, following a problem report submitted to their Problem Reporting Mechanism. Apple initiated an investigation and determined that the OCSP service was incorrectly signing responses with a default OCSP responder when it could not process requests. A fix was rolled out starting October 7, 2019, and completed by October 18, 2019. Apple has since improved their incident reporting processes and shared their OCSP test cases with the community.

Model: gpt-4o-mini Generated: 2026-06-13 15:12 UTC Revised: 2026-06-16 18:01 UTC Confidence: 0.85 27 comments
Chronology
  1. Apple CA was notified of OCSP responders returning incorrect issuer responses.
  2. Apple began rolling out a fix to the OCSP service.
  3. The fix was completed and pushed to all OCSP servers.
Thread Activity
  1. Apple representative — Apple CA acknowledged the issue and began investigating.
  2. Apple representative — Apple provided a detailed incident report and timeline of actions taken.
  3. Apple representative — Apple obtained approval to share their OCSP test cases.
Participants
Apple representative Community commenter Fastly representative Mozilla representative
External References
Similar Local Cases
#1955365 RESOLVED Self Reported Incident Opened 2025-03-20 · Closed 2025-05-19 · 95% similar
Apple: Public Key Reuse
#1841534 RESOLVED Self Reported Incident Certificate Misissuance Opened 2023-07-03 · Closed 2023-08-30 · 94% similar
Apple: TLS certificates issued outside the TTL of the CAA record
#1624527 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-03-24 · Closed 2023-02-22 · 85% similar
DigiCert: Issuance of Cert with Compromised Key
#1650910 RESOLVED Self Reported Incident Audit Finding Revocation Issue Opened 2020-07-06 · Closed 2023-02-22 · 82% similar
DigiCert: Inconsistent EV audits
#1575880 RESOLVED Self Reported Incident Revocation Issue Validation Issue Opened 2019-08-22 · Closed 2023-02-22 · 82% similar
GlobalSign: SSL Certificates with US country code and invalid State/Prov
#1532559 RESOLVED Certificate Misissuance Self Reported Incident Opened 2019-03-05 · Closed 2023-02-22 · 82% similar
CFCA: Wrong SerialNumber encoding
#1623384 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-03-18 · Closed 2023-02-22 · 82% similar
Camerfirma: Invalid authorityKeyIdentifier - recurrent incident
#1563579 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-07-04 · Closed 2023-02-22 · 81% similar
Sectigo: Failure to provide timely incident reports

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action