← Start Commercial (StartCom) Ltd. cases
Bugzilla #1006479
Certificate Problem Report
StartCom: OCSP responder often returns "unknown" for recently-issued certificates
RESOLVED
Start Commercial (StartCom) Ltd.
AI Summary
The StartCom OCSP responder frequently returns 'unknown' for recently issued certificates, causing connection errors for users. This issue arises when certificates are replaced shortly before expiration, leading to delays in the OCSP server's updates. While some browsers may handle this response differently, Firefox's strict rejection of 'unknown' responses can render websites unusable. The case highlights the need for StartCom to improve its OCSP response times to avoid user disruptions.
Chronology
- Initial report of OCSP issues by Martin von Wittich.
- Case assigned to Eddy Nigg for resolution.
- Case resolved with a note on potential future trust.
Participants
Martin von Wittich
Eddy Nigg
Kathleen Wilson
Brian Smith
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
StartCom cert not working in Firefox 4 beta
StartCom: IV without localityName or stateOrProvinceName
StartCom: public exponent is 1
Clarification requested regarding remediation of StartCom certificate issuance vulnerability
Camerfirma: Startcom are issuing by proxy using Camerfirma
EV SSL certificate (and OCSP response) for www.camerfirma.com fails to meet EV Guidelines
StartCom: duplicate serial numbers
DigiCert: Non-BR-Compliant OCSP Responders