← Microsoft Corporation cases
Bugzilla #1620727
Certificate Problem Report
Microsoft DSRE PKI: OCSP responders found to respond signed by the default CA when passed an invalid issuer in request
RESOLVED
DUPLICATE
Microsoft Corporation
AI Summary
Microsoft's OCSP responder was found to incorrectly respond with a certificate signed by the default OCSP responder when an invalid serial number was requested. The issue was reported by a security researcher and subsequently investigated by Microsoft and their OCSP service provider, GlobalSign. It was confirmed that no non-compliant certificates were issued, and a fix was implemented promptly. The case was marked as a duplicate of another Bugzilla report that tracked the issue.
Chronology
- CA team notified of the issue by email
- OCSP fix implemented for all GlobalSign production instances
Participants
Julio Montano
wthayer@fastly.com
External References
Similar Local Cases
Microsoft PKI Services: Null Character Bug and Microsoft Root CAs
Microsoft PKI Services: Loss of Archived Firewall logs from Retention Store
Microsoft DSRE PKI: problem reporting e-mail in CPS does not work
GlobalSign: OCSP responders found to respond signed by the default CA when passed an invalid issuer in request
Microsoft PKI Services: Malformed ICAs (missing certificate policy extensions)
Microsoft DSRE PKI: Microsoft shares wildcard certificates among cloud instances
Microsoft PKI Services: OCSP Responder does not know a Certificate
Camerfirma: Multicert SSL CA 001: Insufficient serial number entropy