Microsoft DSRE PKI: OCSP responders signed by default OCSP responder certificate when invalid serial number is requested
The bug was filed after an external security researcher (Oscar Karlsson) informed Microsoft of an OCSP behavior issue. Microsoft reported that when an OCSP request contains an invalid serial number, the OCSP responder returns an “unknown” status signed by the default OCSP responder certificate, rather than an unauthorized/unsigned response. Microsoft stated that there were no non-compliant certificates issued and that the OCSP fix was implemented for all GlobalSign production OCSP instances on December 20, 2019. Microsoft also notified GlobalSign to investigate and confirmed the described behavior during its investigation. Microsoft referenced additional timeline details in a separate Bugzilla created by DigiCert (bug 1605372) and noted that this bug was filed out of caution even though the OCSP provider had already filed and closed a bug for the issue. The current resolution of this bug is marked as a duplicate of bug 1605372.
- Microsoft’s CA team was notified that its OCSP responder behavior for invalid serial numbers resulted in responses signed by the default OCSP responder certificate.
- GlobalSign production OCSP instances were updated with the OCSP fix.
- Microsoft Corporation — Filed the bug describing the OCSP issue, stating there were no non-compliant certificates issued and that the OCSP fix was implemented on December 20, 2019, and marked the bug as a duplicate of bug 1605372.
- Fastly representative — Agreed with Microsoft’s decision to file the CA compliance bug in this case and thanked Julio for referencing the GlobalSign bug.