Sectigo: "unauthorized" OCSP responses for expired certificates
The bug was opened by m**********r@hezmatt.org after observing OCSP responses that returned HTTP 200 OK but an OCSP status of 6 (“unauthorized”) for two specific certificates queried via http://ocsp.comodoca.com. The reporter noted the same OCSP responders returned successful results for other certificates. Sectigo (Robin Alden) responded that both affected certificates were expired and that Sectigo does not generate OCSP responses for expired SSL certificates. Another participant (r**********b@sectigo.com) explained that the CA uses RFC 5019’s extended definition of “unauthorized,” including that the responder may remove status records for expired certificates, which can lead to an “unauthorized” OCSPResponseStatus when records are removed. The reporter acknowledged the issue as an incorrect report and apologized for the corner case. The bug was resolved as INVALID.
- A third party reported that OCSP queries for two certificates returned OCSP status 6 (“unauthorized”) despite HTTP 200 OK.
- Sectigo stated the certificates were expired and that it does not generate OCSP responses for expired SSL certificates.
- Sectigo cited RFC 5019 behavior for expired certificates and “unauthorized” OCSPResponseStatus when records are removed.
- The reporter acknowledged the report was incorrect and apologized.
- Hezmatt representative — Reported that OCSP responses for two crt.sh-listed certificates returned OCSP status 6 (“unauthorized”) while HTTP status was 200 OK, and that other certificates worked as expected.
- Sectigo — Said both certificates were expired and that Sectigo does not generate OCSP responses for expired SSL certificates.
- Community commenter — Apologized and said they would open an issue on crt.sh to make the behavior more prominent.
- Sectigo — Explained the CA uses RFC 5019’s extended definition of “unauthorized,” including that status records for expired certificates may be removed, leading to OCSPResponseStatus “unauthorized,” and referenced a crt.sh certwatch issue.
- Hezmatt representative — Apologized and stated the report was incorrect due to the expired-certificate corner case.