← DigiCert cases
Bugzilla #1627152 Ca Certificate Compliance Self Reported Incident

DigiCert: OCSP nextUpdate field requirement for legacy s/MIME platform

RESOLVED FIXED DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

DigiCert filed an incident report to Mozilla describing a Mozilla policy violation related to OCSP responses for a subset of legacy s/MIME certificates. DigiCert became aware of the issue through SubCA communications requesting clarification about a requirement that OCSP responses “MUST have a defined value in the nextUpdate field” and that it “MUST be no more than ten days after the thisUpdate field.” After investigating, DigiCert determined that the customer’s OCSP software (DigiCert-provided software) does not permit customers to include a thisUpdate value in OCSP responses, and that the issue is limited to DigiCert’s legacy Symantec on-prem CA platform (MPKI7) used for s/MIME and private certs. DigiCert stated it had not stopped issuance, and that the issue applies to revocation information that is still being provided. DigiCert reported that the root cause was that the software was developed to meet RFC 6960 (where nextUpdate is optional) rather than the Mozilla requirement, and that the Mozilla requirement was missed during review of the legacy software. DigiCert completed a patch to set a nextUpdate field compliant with Mozilla Root Store Policy, released it to customers, and reported successful production deployment by the last customer; the bug was then requested to be closed and Fastly indicated remediation was complete.

Model: gpt-5.4-nano Generated: 2026-06-13 11:37 UTC Revised: 2026-06-16 19:02 UTC Confidence: 0.90 7 comments
Chronology
  1. A SubCA requested clarification about the Mozilla OCSP nextUpdate requirement for s/MIME certificates.
  2. DigiCert confirmed the OCSP responses lacked the nextUpdate field and began root cause analysis.
  3. DigiCert filed the initial incident report to Mozilla.
  4. DigiCert reported the OCSP fix patch was completed and undergoing QA.
  5. DigiCert released the OCSP fix to customers and one customer tested and deployed it to production.
  6. The last customer deployed the OCSP fix into production successfully.
Thread Activity
  1. DigiCert — Opened the incident report describing the OCSP nextUpdate policy violation for legacy s/MIME certificates, the scope limitation to MPKI7, and the planned compliant nextUpdate patch.
  2. Community commenter — Asked about the long time gap and requested guidance/attachments to assess scope and potential impact.
  3. DigiCert — Explained the time gap as multiple simultaneous CPS reviews and said she would provide the requested certificate information attachment by April 8.
  4. DigiCert — Provided crt.sh IDs for certificates in scope and stated the patch was completed and in QA, with an update after release/testing.
  5. DigiCert — Reported the patch was released to customers early that week and one customer had deployed to production.
  6. DigiCert — Updated that the last customer deployed the OCSP fix into production and requested the bug be closed if no further questions.
  7. Fastly representative — Noted it appeared all questions were answered and remediation was complete.
Participants
DigiCert Community commenter Fastly representative
Similar Local Cases
#1710444 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2021-05-10 · Closed 2023-02-22 · 90% similar
DigiCert: Invalid stateOrProvinceName
#1714439 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2021-06-03 · Closed 2023-02-22 · 90% similar
DigiCert: Incorrect RegNumber-Org Type combination
#1397960 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-09-07 · Closed 2023-02-22 · 89% similar
DigiCert / Telecom Italia: Several Problems
#1618256 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-02-26 · Closed 2023-02-22 · 88% similar
DigiCert: Failure to properly encode Subject name
#1624527 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-03-24 · Closed 2023-02-22 · 88% similar
DigiCert: Issuance of Cert with Compromised Key
#1335132 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-01-30 · Closed 2023-02-22 · 88% similar
DigiCert: Verizon mis-issued test certificates
#1397961 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-09-07 · Closed 2023-02-22 · 88% similar
DigiCert / Justica: Invalid DNS names
#1429639 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2018-01-11 · Closed 2023-02-22 · 88% similar
DigiCert: BR 3.2.5 Validation of Authority Failure for OV Certs

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action