← Microsoft Corporation cases
Bugzilla #1620727 Ca Certificate Compliance Incident

Microsoft DSRE PKI: OCSP responders signed by default OCSP responder certificate when invalid serial number is requested

RESOLVED DUPLICATE Microsoft Corporation
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The bug was filed after an external security researcher (Oscar Karlsson) informed Microsoft of an OCSP behavior issue. Microsoft reported that when an OCSP request contains an invalid serial number, the OCSP responder returns an “unknown” status signed by the default OCSP responder certificate, rather than an unauthorized/unsigned response. Microsoft stated that there were no non-compliant certificates issued and that the OCSP fix was implemented for all GlobalSign production OCSP instances on December 20, 2019. Microsoft also notified GlobalSign to investigate and confirmed the described behavior during its investigation. Microsoft referenced additional timeline details in a separate Bugzilla created by DigiCert (bug 1605372) and noted that this bug was filed out of caution even though the OCSP provider had already filed and closed a bug for the issue. The current resolution of this bug is marked as a duplicate of bug 1605372.

Model: gpt-5.4-nano Generated: 2026-06-13 21:11 UTC Revised: 2026-06-16 19:12 UTC Confidence: 0.86 3 comments
Chronology
  1. Microsoft’s CA team was notified that its OCSP responder behavior for invalid serial numbers resulted in responses signed by the default OCSP responder certificate.
  2. GlobalSign production OCSP instances were updated with the OCSP fix.
Thread Activity
  1. Microsoft Corporation — Filed the bug describing the OCSP issue, stating there were no non-compliant certificates issued and that the OCSP fix was implemented on December 20, 2019, and marked the bug as a duplicate of bug 1605372.
  2. Fastly representative — Agreed with Microsoft’s decision to file the CA compliance bug in this case and thanked Julio for referencing the GlobalSign bug.
Participants
Microsoft Corporation Fastly representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1604124 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Opened 2019-12-16 · Closed 2023-02-22 · 86% similar
Microsoft DSRE PKI: problem reporting e-mail in CPS does not work
#1398246 RESOLVED Ca Certificate Compliance Incident Opened 2017-09-08 · Closed 2023-02-22 · 79% similar
Consorci AOC: Non-BR-Compliant OCSP Responders
#1602999 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Opened 2019-12-11 · Closed 2024-05-09 · 77% similar
Microsoft PKI Services: Loss of Archived Firewall logs from Retention Store
#2009543 RESOLVED Ca Certificate Compliance Incident Repository Issue Opened 2026-01-10 · Closed 2026-02-09 · 70% similar
Microsoft PKI Services: Improper Disclosure of CRLs – Does Not Match CA Subject
#2056223 ASSIGNED Ca Certificate Compliance Incident Externally Reported Incident Policy Document Issue Opened 2026-07-20 Still Open · 69% similar
D-Trust OCSP Responder Certificates Include CA/B Forum DV Policy OID
#2009545 RESOLVED Ca Certificate Compliance Incident Repository Issue Opened 2026-01-10 · Closed 2026-02-11 · 69% similar
Microsoft PKI Services: Improper Disclosure of CRLs – Protocol Scheme
#1582519 RESOLVED Incident Opened 2019-09-19 · Closed 2022-11-14 · 69% similar
DigiCert: Apple: Precertificates without corresponding certificates return OCSP value of "unknown"
#1367842 RESOLVED Ca Certificate Compliance Incident Opened 2017-05-25 · Closed 2023-02-22 · 69% similar
TurkTrust: Non-audited, non-technically-constrained intermediate certs

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action