← GlobalSign nv-sa cases
Bugzilla #1622505
Certificate Problem Report
GlobalSign: OCSP Status HTTP 530
RESOLVED
FIXED
GlobalSign nv-sa
AI Summary
GlobalSign experienced an outage in one of its data centers, leading to instability in OCSP responder availability. This incident caused users to encounter SEC_ERROR_OCSP_SERVER_ERROR when accessing certain services. The issue was attributed to a combination of unforeseen traffic increases and malicious traffic, which were mitigated over time. GlobalSign has since implemented improvements to its disaster recovery plans and incident communication processes to prevent future occurrences.
Chronology
- Issue begins with response time problems.
- Malicious traffic identified and mitigated.
- All services operational again.
- Detailed review of disaster recovery plans completed.
Participants
tdelmas@gmail.com
arvid.vermote@globalsign.com
ryan.sleevi@gmail.com
bwilson@mozilla.com
External References
Similar Local Cases
GlobalSign: Failure to revoke key-compromised certificate within 24 hours
GlobalSign: SPKI lacks explicit NULL parameter,
GlobalSign: OCSP Responder Returns invalid values for Some Precertificates
Apple: OCSP availability 2020-11-12
Asseco DS / Certum: Incorrect OCSP response encoding
SSL.com: Issuance of 3 EV TLS certificates without 2-person validation of the organization information
GlobalSign: SSL Certificates with US country code and invalid State/Prov
TunTrust: OCSP unreachable