← Google Trust Services LLC cases
Bugzilla #1630040 Self Reported Incident

Google Trust Services: OCSP serving issue 2020-04-09

RESOLVED FIXED Google Trust Services LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Google Trust Services reported an OCSP serving issue affecting its EJBCA-based CAs (GIAG4, GIAG4ECC, GTSY1-4) during 2020-04-08 16:25 UTC to 2020-04-09 05:40 UTC, when empty OCSP data was served and OCSP responders returned unauthorized. Mozilla’s CA Program case describes how monitoring detected the issue on 2020-04-08 at 16:35 UTC and how the problem self-corrected after correct OCSP archives and responses were generated and pushed to the CDN. Google stated that the affected CAs are used for infrequent, manual custom certificate issuance for test sites for inactive roots, and that no certificate issuance aside from a manually issued post-update test certificate occurred during the period. Google attributed the root cause to a scripting/error-handling problem: a non-zero exit code from a tool fetching OCSP responses was suppressed in an AND/OR context, leading the script to use empty tar.gz files when EJBCA was not running. Google said it added safeguards to prevent recurrence, including additional pre-push checks for readable tar.gz, at least one OCSP response in the archive, and at least one OCSP response per CA. The bug was resolved as FIXED, and Google later confirmed the described changes went into production at the end of April and that remediation was complete.

Model: gpt-5.4-nano Generated: 2026-06-13 21:20 UTC Revised: 2026-06-16 18:34 UTC Confidence: 0.86 10 comments
Chronology
  1. Incorrect OCSP archives were generated and incorrect OCSP responses were pushed to the CDN for affected EJBCA-based CAs.
  2. Production monitoring detected the OCSP serving issue via the first monitoring alert.
  3. Correct OCSP archives and responses were generated and pushed to the CDN; monitoring confirmed probes were passing.
Thread Activity
  1. Google representative — Opened the bug describing the OCSP serving issue, its timeline, root cause, and the safeguards added to prevent recurrence; stated the issue self-corrected and remediation was implemented.
  2. Community commenter — Asked for clarification on why prior OCSP testing did not catch the issue and requested more detail on GTS OCSP processes and monitoring.
  3. Google representative — Provided additional context on GTS OCSP/revocation infrastructure stacks and described improvements, including adding a pre-push check for the empty-bundle condition.
  4. Community commenter — Acknowledged the context and asked for more detail on the existing pre-push checks and what is being added.
  5. Google representative — Explained additional pre-push (presubmit) checks planned for the next production update, including tar.gz readability and presence of OCSP responses.
  6. Community commenter — Noted another production revocation incident in a separate bug and suggested a pattern of revocation-related issues.
  7. Fastly representative — Asked whether the update described in the safeguards comment had been deployed and when it was expected.
  8. Google representative — Confirmed the changes went into production at the end of April shortly after the referenced update.
  9. Fastly representative — Confirmed remediation appeared complete after questions were answered.
Participants
Google representative Community commenter Mozilla representative Fastly representative
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#1630079 RESOLVED Self Reported Incident Opened 2020-04-14 · Closed 2023-02-22 · 100% similar
Google Trust Services: Invalid OCSP responses
#1979457 RESOLVED Self Reported Incident Opened 2025-07-25 · Closed 2025-10-22 · 81% similar
Google Trust Services: Missing authorization audit log entry for certificate issuance
#2032511 RESOLVED Ca Security Vulnerability Self Reported Incident Opened 2026-04-16 · Closed 2026-05-29 · 81% similar
Google Trust Services: Short OCSP outage
#1770510 RESOLVED Self Reported Incident Opened 2022-05-20 · Closed 2023-05-04 · 79% similar
Google Trust Services: Failure to provide preliminary report within 24h
#1815874 RESOLVED Self Reported Incident Opened 2023-02-09 · Closed 2023-03-20 · 79% similar
Google Trust Services: incorrect SCT in certificate
#1525710 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-02-06 · Closed 2023-02-22 · 77% similar
Amazon Trust Services: Test revoked certificates with invalid validity period
#1579950 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-09-09 · Closed 2022-11-14 · 76% similar
QuoVadis: OCSP handling of Certificate Transparency Pre-certs
#1544712 RESOLVED Self Reported Incident Opened 2019-04-16 · Closed 2023-02-22 · 76% similar
SECOM: certificate for which “OU=-”

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action