← Sectigo cases
Bugzilla #1639518
Certificate Problem Report
Sectigo: "unauthorized" OCSP responses
RESOLVED
INVALID
Sectigo
AI Summary
A user reported receiving "unauthorized" OCSP responses for two expired certificates from Sectigo. The user expected a successful response but received an HTTP 200 status with an OCSP status of 6. Sectigo clarified that they do not generate OCSP responses for expired certificates, which aligns with RFC5019's definition of "unauthorized". The issue was acknowledged as a misunderstanding by the user, who typically does not handle expired certificates.
Chronology
- User reports unauthorized OCSP responses.
- Sectigo confirms OCSP responses are not generated for expired certificates.
- User acknowledges misunderstanding regarding expired certificates.
Participants
mpalmer@hezmatt.org
Robin.Alden@Sectigo.com
ryan.sleevi@gmail.com
rob@sectigo.com
External References
Similar Local Cases
Sectigo: Failure to revoke key-compromised certificate within 24 hours
Sectigo: potentially invalid organizational validation certificates
Let's Encrypt: Failure to revoke key-compromised certificate within 24 hours
SwissSign: failure to provide a preliminary report within 24 hours
Sectigo: Partial OCSP response publication delay for newly issued certificates
Sectigo: OCSP responses directly signed using root certificates without KU=digitalSignature
Sectigo: Premature disabling of CRL generation for an inactive CA
Sectigo: OCSP and CRL traffic not being proxied for 3 Subordinate CAs