← IdenTrust Services, LLC cases
Bugzilla #1636544 Self Incident Disclosure

IdenTrust: OCSP Outage

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The case concerns an OCSP outage experienced by IdenTrust around April 25, 2020, affecting the OCSP responder URI http://isrg.trustid.ocsp.identrust.com. An external report (referenced in the bug) alleged a multi-day OCSP outage, and IdenTrust acknowledged receipt and began investigating. IdenTrust reported that on 2020-04-23 15:01 (GMT) there was a significant spike in requests to the OCSP responder, peaking at 650k requests per second versus a typical 10k rps, and that the exact cause of the spike was unknown. IdenTrust stated that the spike led the ISRG OCSP responder to start serving errors and that the firewall at the primary data center became unresponsive; after monitoring alerted them to potential impact, they troubleshot and later performed a hard boot on the firewall, after which the request rate returned to normal and the OCSP responder stopped serving errors. IdenTrust also stated that the outage was lengthened by the hard boot requiring air travel to the datacenter, during which users of the OCSP responder were receiving errors. In response to questions about DR testing, IdenTrust stated that OCSP validation servers are part of annual DR testing and that the monitoring method used during the last DR exercise did not detect issues related to traffic switch between CDN and their sites. IdenTrust later reported completion of enhanced end-to-end monitoring for the affected OCSP responder to detect user-facing availability issues, and Mozilla indicated an intent to close the bug on or after 5-Aug-2020 unless new issues arose.

Model: gpt-5.4-nano Generated: 2026-06-13 21:11 UTC Revised: 2026-06-16 19:15 UTC Confidence: 0.86 8 comments
Chronology
  1. IdenTrust experienced a significant spike in OCSP responder requests to http://isrg.trustid.ocsp.identrust.com.
  2. The OCSP responder began serving errors and IdenTrust performed troubleshooting and a hard boot of the primary data center firewall.
  3. IdenTrust became aware via the community that relying parties may have experienced service disruption and provided an incident summary.
  4. IdenTrust completed enhanced end-to-end monitoring implementation for the affected OCSP responder.
Thread Activity
  1. Fastly representative — Requested that IdenTrust explain or provide an incident report after a report alleged a multi-day OCSP outage around April 25, 2020.
  2. IdenTrust Services, LLC — Acknowledged receipt and said they would start investigating.
  3. IdenTrust Services, LLC — Reported progress investigating and said a formal response would be coordinated by May 22, 2020.
  4. IdenTrust Services, LLC — Provided an incident summary including the request spike, resulting errors, firewall unresponsiveness, troubleshooting, and the hard boot that ended the errors.
  5. Fastly representative — Asked whether OCSP failover is part of IdenTrust’s DR procedures and why the issue was not detected during DR review/testing.
  6. IdenTrust Services, LLC — Answered that OCSP validation servers are part of annual DR testing and that monitoring used in the last DR exercise did not detect issues related to CDN-to-origin traffic switching; said monitoring would be updated.
  7. IdenTrust Services, LLC — Reported completion of enhanced end-to-end monitoring for http://isrg.trustid.ocsp.identrust.com to detect user-facing availability issues.
  8. Mozilla representative — Stated an intent to close the bug on or after 5-Aug-2020 unless additional issues or questions were raised.
Participants
Fastly representative IdenTrust Services, LLC Mozilla representative
Similar Local Cases
#1653680 RESOLVED Self Incident Disclosure Opened 2020-07-17 · Closed 2023-02-22 · 61% similar
IdenTrust: OCSP Responder missing id-pkix-ocsp-nocheck
#1758027 RESOLVED Self Incident Disclosure Opened 2022-03-04 · Closed 2023-02-22 · 61% similar
IdenTrust: Pre-certificates without a final certificate showing OCSP error
#1905446 RESOLVED Incident Opened 2024-06-28 · Closed 2024-12-09 · 60% similar
IdenTrust: Unauthorized OCSP response on a Timestamp certificate
#1778788 RESOLVED Self Incident Disclosure Opened 2022-07-08 · Closed 2023-02-22 · 60% similar
IdenTrust: Intermittent issuance/validation failures and website outage
#1838315 RESOLVED Ca Security Vulnerability Incident Opened 2023-06-13 · Closed 2023-10-12 · 60% similar
IdenTrust: Certificate with missing details flagged by OCSP Watch
#1933353 RESOLVED Self Reported Incident Opened 2024-11-25 · Closed 2025-03-21 · 59% similar
IdenTrust: Incorrect response for OCSP validation
#1709192 RESOLVED Incident Opened 2021-05-03 · Closed 2023-02-22 · 59% similar
IdenTrust: Unavailable CRL for IdenTrust ‘DST Root CA X3’.
#1718552 RESOLVED Certificate Misissuance Opened 2021-06-28 · Closed 2023-02-22 · 59% similar
IdenTrust: Certificates with Invalid values for stateOrProvinceName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action