← GlobalSign nv-sa cases
Bugzilla #1622505
Ca Security Vulnerability
GlobalSign: OCSP Status HTTP 530
RESOLVED
FIXED
GlobalSign nv-sa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
This case involves GlobalSign's disclosure of an incident affecting their OCSP responder services, which resulted in HTTP 530 errors. The issue was triggered by instability at one of their data centers, leading to intermittent failures in OCSP responses. GlobalSign acknowledged the problem and provided an incident report detailing the timeline of events and the actions taken to mitigate the issue. The CA has since implemented improvements to their disaster recovery plans and incident communication processes to prevent future occurrences. The case is now resolved with the status marked as FIXED.
Chronology
- GlobalSign's monitoring tools identified issues with OCSP response times.
- All services were restored and operational.
Thread Activity
- Community commenter — Reported OCSP server errors while accessing a specific URL.
- GlobalSign nv-sa — Confirmed instability at a data center and stated it would be resolved shortly.
- GlobalSign nv-sa — Attached an incident report detailing the outage.
- GlobalSign nv-sa — Provided a timeline of actions taken in response to the incident.
- GlobalSign nv-sa — Updated on the completion of reviews and improvements to incident communication.
- Mozilla representative — Inquired about the status of the incident report and whether the case could be closed.
Participants
Community commenter
GlobalSign nv-sa
Mozilla representative
External References
Similar Local Cases
DigiCert: OCSP responder returning invalid responses
GlobalSign: Invalid stateOrProvinceName value
GlobalSign: Invalid countryName
GlobalSign: RSA-1024 leaf certificate issued after 2013-12-31
TWCA: "unknown" OCSP response for issued certificates
GlobalSign: Invalid stateOrProvinceName and locality pair
GoDaddy: Intermittent unauthorized OCSP response when certificate is freshly issued
Google Trust Services: Incorrect OCSP responses for certain certificates