← Apple Inc. cases
Bugzilla #1588001
Self Reported Incident
Apple: OCSP responders return responses with incorrect issuer
RESOLVED
FIXED
Apple Inc.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
Apple CA reported an incident where their OCSP responders were returning signed responses with incorrect issuers. The issue was identified on October 3, 2019, following a problem report submitted to their Problem Reporting Mechanism. Apple initiated an investigation and determined that the OCSP service was incorrectly signing responses with a default OCSP responder when it could not process requests. A fix was rolled out starting October 7, 2019, and completed by October 18, 2019. Apple has since improved their incident reporting processes and shared their OCSP test cases with the community.
Chronology
- Apple CA was notified of OCSP responders returning incorrect issuer responses.
- Apple began rolling out a fix to the OCSP service.
- The fix was completed and pushed to all OCSP servers.
Thread Activity
- Apple representative — Apple CA acknowledged the issue and began investigating.
- Apple representative — Apple provided a detailed incident report and timeline of actions taken.
- Apple representative — Apple obtained approval to share their OCSP test cases.
Participants
Apple representative
Community commenter
Fastly representative
Mozilla representative
External References
Similar Local Cases
Apple: Public Key Reuse
Apple: TLS certificates issued outside the TTL of the CAA record
DigiCert: Issuance of Cert with Compromised Key
DigiCert: Inconsistent EV audits
GlobalSign: SSL Certificates with US country code and invalid State/Prov
CFCA: Wrong SerialNumber encoding
Camerfirma: Invalid authorityKeyIdentifier - recurrent incident
Sectigo: Failure to provide timely incident reports