← Google Trust Services LLC cases
Bugzilla #1630040
Certificate Problem Report
Google Trust Services: OCSP serving issue 2020-04-09
RESOLVED
FIXED
Google Trust Services LLC
AI Summary
Google Trust Services experienced an OCSP serving issue from April 8 to April 9, 2020, where empty OCSP data was served, leading to unauthorized responses. The problem was detected through monitoring, and the root cause was identified quickly. Safeguards have since been implemented to prevent recurrence. The affected CAs were primarily used for custom certificate issuance, and no significant certificate issuance occurred during the incident.
Chronology
- Scheduled system update begins
- Incorrect OCSP archives generated
- First production monitoring alert fires
- Monitoring confirms all probes are passing
Participants
Andy Warner
Ryan Sleevi
External References
Similar Local Cases
Google Trust Services: Incorrect revocation data temporarily served for GTS Y3 & Y4
Google Trust Services: Invalid OCSP responses
Google Trust Services: Forbidden Domain Validation Method 3.2.2.4.10
Google Trust Services: Invalid ASN.1 encoding of singleExtensions in OCSP responses
Google Trust Services: Improper OCSP response for intermediate certificate
Google Trust Services: CRL handling of expired certificates not fully compliant with RFC 5280 Section 3.3
Google Trust Services: Failure to revoke subscriber certificates within BR timeframe
Google Trust Services: Missing authorization audit log entry for certificate issuance