GlobalSign: OCSP responders responded with the default CA signer when an invalid issuer was provided
This case reports an OCSP responder behavior issue affecting GlobalSign’s OCSP infrastructure. Paul Brown stated that Microsoft informed GlobalSign of an issue with Microsoft’s OCSP responder that had been reported by a security researcher, and GlobalSign identified the issue on its OCSP cluster. GlobalSign linked the issue to an EJBCA problem (ECA-8620) and stated that no non-compliant certificates were issued. As remediation, GlobalSign disabled the default OCSP signer so that the system would respond with “Unauthorized (unsigned)” rather than an unknown signed response from a default signer, and then updated production OCSP clusters with the workaround. In a later update, GlobalSign stated that remediation steps were completed by removing the default responders and that new CA Certificate Compliance Bugzilla tickets now automatically create SOC incident-management tickets that must be investigated and signed off by the relevant team. The bug was marked RESOLVED with resolution FIXED, and Microsoft later noted that Bug 1620727 was marked as a duplicate of this bug.
- Microsoft informed GlobalSign of an OCSP responder issue reported by a security researcher; GlobalSign identified the issue on its OCSP cluster later that day.
- GlobalSign matched the issue to EJBCA issue ECA-8620 and noted a fix was on staging but not ready for production.
- GlobalSign identified a workaround and updated the first production OCSP cluster with it.
- GlobalSign scheduled updates of other OCSP clusters to complete the workaround rollout.
- GlobalSign confirmed remediation was complete and described SOC incident-management integration for future CA Certificate Compliance tickets.
- Microsoft indicated Bug 1620727 was marked as a duplicate of this bug.
- GlobalSign nv-sa — Paul Brown provided an incident report describing how GlobalSign became aware of the OCSP issue, the timeline of investigation and remediation, and stated that no non-compliant certificates were issued.
- Fastly representative — Wayne Thayer asked clarifying questions about the Microsoft notification, the workaround, and whether Primekey notified customers.
- Community commenter — Ryan Sleevi asked which OCSP responders were affected to map scope and impact.
- GlobalSign nv-sa — Paul Brown clarified that a security researcher informed Microsoft, Microsoft informed GlobalSign, described the workaround (disabling the default OCSP signer), and stated that for TLS only Microsoft and GlobalSign OCSP responders were affected.
- Fastly representative — Wayne Thayer asked Paul to confirm that all remediation steps had been completed.
- GlobalSign nv-sa — Paul Brown confirmed remediation was complete (default responders removed) and stated that new CA Certificate Compliance Bugzilla tickets now automatically create SOC incident-management tickets for investigation and sign-off.
- Fastly representative — Wayne Thayer stated it appeared all questions were answered and remediation was complete.
- Microsoft Corporation — Julio Montano noted that Bug 1620727 was marked as a duplicate of this bug.