DigiCert: OCSP nextUpdate field requirement for legacy s/MIME platform
DigiCert filed an incident report to Mozilla describing a Mozilla policy violation related to OCSP responses for a subset of legacy s/MIME certificates. DigiCert became aware of the issue through SubCA communications requesting clarification about a requirement that OCSP responses “MUST have a defined value in the nextUpdate field” and that it “MUST be no more than ten days after the thisUpdate field.” After investigating, DigiCert determined that the customer’s OCSP software (DigiCert-provided software) does not permit customers to include a thisUpdate value in OCSP responses, and that the issue is limited to DigiCert’s legacy Symantec on-prem CA platform (MPKI7) used for s/MIME and private certs. DigiCert stated it had not stopped issuance, and that the issue applies to revocation information that is still being provided. DigiCert reported that the root cause was that the software was developed to meet RFC 6960 (where nextUpdate is optional) rather than the Mozilla requirement, and that the Mozilla requirement was missed during review of the legacy software. DigiCert completed a patch to set a nextUpdate field compliant with Mozilla Root Store Policy, released it to customers, and reported successful production deployment by the last customer; the bug was then requested to be closed and Fastly indicated remediation was complete.
- A SubCA requested clarification about the Mozilla OCSP nextUpdate requirement for s/MIME certificates.
- DigiCert confirmed the OCSP responses lacked the nextUpdate field and began root cause analysis.
- DigiCert filed the initial incident report to Mozilla.
- DigiCert reported the OCSP fix patch was completed and undergoing QA.
- DigiCert released the OCSP fix to customers and one customer tested and deployed it to production.
- The last customer deployed the OCSP fix into production successfully.
- DigiCert — Opened the incident report describing the OCSP nextUpdate policy violation for legacy s/MIME certificates, the scope limitation to MPKI7, and the planned compliant nextUpdate patch.
- Community commenter — Asked about the long time gap and requested guidance/attachments to assess scope and potential impact.
- DigiCert — Explained the time gap as multiple simultaneous CPS reviews and said she would provide the requested certificate information attachment by April 8.
- DigiCert — Provided crt.sh IDs for certificates in scope and stated the patch was completed and in QA, with an update after release/testing.
- DigiCert — Reported the patch was released to customers early that week and one customer had deployed to production.
- DigiCert — Updated that the last customer deployed the OCSP fix into production and requested the bug be closed if no further questions.
- Fastly representative — Noted it appeared all questions were answered and remediation was complete.