← Google Trust Services LLC cases
Bugzilla #1630079 Self Reported Incident

Google Trust Services: Invalid OCSP responses

RESOLVED FIXED Google Trust Services LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case documents an incident involving Google Trust Services (GTS) OCSP generation. On 2018-01-19, GTS initiated a code push to improve OCSP generation for a subset of Google-operated Certificate Authorities, related to packaging generated OCSP responses. The change triggered unexpected behavior in GNU tar that manifested as empty tarballs, which were distributed to the global CDN and effectively dropped some OCSP responses while continuing to serve updates. The issue was not noticed by Google employees until after a post-mortem investigation began, and remediation procedures were triggered after discovery. The incident report states the issue was resolved about 2 days and 6 hours from when it was introduced, with additional time for the fix to be fully deployed. In this Bugzilla thread, Ryan Sleevi opened the bug for bookkeeping after noticing a prior incident bug was missing, and Andy Warner stated GTS had nothing additional to add and that the affected CA infrastructure was turned down and new pipelines include checks for the January 2018 issue. The bug was resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:21 UTC Revised: 2026-06-16 18:34 UTC Confidence: 0.86 4 comments
Chronology
  1. GTS deployed a code push intended to improve OCSP generation packaging for a subset of Google-operated CAs.
  2. GTS discovered the issue via a mailing list post and began remediation procedures.
  3. GTS resolved the OCSP issue and completed deployment after additional propagation time.
  4. A Bugzilla entry was filed for bookkeeping regarding the January 2018 OCSP incident.
Thread Activity
  1. Community commenter — Filed the bug for bookkeeping, describing the January 2018 OCSP incident and providing the incident report details.
  2. Community commenter — Noted that in responding to Bug 1630040 they found no prior bug for the previous incident and suggested resolving/fixing for accounting purposes.
  3. Google representative — Confirmed GTS had nothing additional to add and stated the affected infrastructure was turned down and new pipelines include checks for the January 2018 issue.
  4. Fastly representative — Resolved the bug per comment #1.
Participants
Community commenter Google representative Fastly representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1630040 RESOLVED Self Reported Incident Opened 2020-04-14 · Closed 2023-02-22 · 100% similar
Google Trust Services: OCSP serving issue 2020-04-09
#1979457 RESOLVED Self Reported Incident Opened 2025-07-25 · Closed 2025-10-22 · 80% similar
Google Trust Services: Missing authorization audit log entry for certificate issuance
#2032511 RESOLVED Ca Security Vulnerability Self Reported Incident Opened 2026-04-16 · Closed 2026-05-29 · 80% similar
Google Trust Services: Short OCSP outage
#1770510 RESOLVED Self Reported Incident Opened 2022-05-20 · Closed 2023-05-04 · 79% similar
Google Trust Services: Failure to provide preliminary report within 24h
#1815874 RESOLVED Self Reported Incident Opened 2023-02-09 · Closed 2023-03-20 · 78% similar
Google Trust Services: incorrect SCT in certificate
#1538638 RESOLVED Ca Certificate Compliance Self Reported Incident Revocation Issue Opened 2019-03-25 · Closed 2023-02-22 · 76% similar
Firmaprofesional: AC Firmaprofesional - INFRAESTRUCTURA insufficient serial number entropy
#1650910 RESOLVED Self Reported Incident Audit Finding Revocation Issue Opened 2020-07-06 · Closed 2023-02-22 · 75% similar
DigiCert: Inconsistent EV audits
#1484766 RESOLVED Self Reported Incident Revocation Issue Security Incident Opened 2018-08-20 · Closed 2024-06-30 · 75% similar
GoDaddy: Random Value Vulnerability in Domain Validation Method

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action