← Sectigo cases
Bugzilla #1639518 Certificate Misissuance

Sectigo: "unauthorized" OCSP responses for expired certificates

RESOLVED INVALID Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The bug was opened by m**********r@hezmatt.org after observing OCSP responses that returned HTTP 200 OK but an OCSP status of 6 (“unauthorized”) for two specific certificates queried via http://ocsp.comodoca.com. The reporter noted the same OCSP responders returned successful results for other certificates. Sectigo (Robin Alden) responded that both affected certificates were expired and that Sectigo does not generate OCSP responses for expired SSL certificates. Another participant (r**********b@sectigo.com) explained that the CA uses RFC 5019’s extended definition of “unauthorized,” including that the responder may remove status records for expired certificates, which can lead to an “unauthorized” OCSPResponseStatus when records are removed. The reporter acknowledged the issue as an incorrect report and apologized for the corner case. The bug was resolved as INVALID.

Model: gpt-5.4-nano Generated: 2026-06-13 20:58 UTC Revised: 2026-06-16 18:44 UTC Confidence: 0.86 5 comments
Chronology
  1. A third party reported that OCSP queries for two certificates returned OCSP status 6 (“unauthorized”) despite HTTP 200 OK.
  2. Sectigo stated the certificates were expired and that it does not generate OCSP responses for expired SSL certificates.
  3. Sectigo cited RFC 5019 behavior for expired certificates and “unauthorized” OCSPResponseStatus when records are removed.
  4. The reporter acknowledged the report was incorrect and apologized.
Thread Activity
  1. Hezmatt representative — Reported that OCSP responses for two crt.sh-listed certificates returned OCSP status 6 (“unauthorized”) while HTTP status was 200 OK, and that other certificates worked as expected.
  2. Sectigo — Said both certificates were expired and that Sectigo does not generate OCSP responses for expired SSL certificates.
  3. Community commenter — Apologized and said they would open an issue on crt.sh to make the behavior more prominent.
  4. Sectigo — Explained the CA uses RFC 5019’s extended definition of “unauthorized,” including that status records for expired certificates may be removed, leading to OCSPResponseStatus “unauthorized,” and referenced a crt.sh certwatch issue.
  5. Hezmatt representative — Apologized and stated the report was incorrect due to the expired-certificate corner case.
Participants
Hezmatt representative Sectigo Community commenter
Similar Local Cases
#1717046 RESOLVED Certificate Misissuance Opened 2021-06-17 · Closed 2022-11-14 · 87% similar
Sectigo: potentially invalid organizational validation certificates
#1910451 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-07-29 · Closed 2024-08-21 · 77% similar
Sectigo: Missing character in subject:organizationName attribute value
#1398269 RESOLVED Certificate Misissuance Opened 2017-09-08 · Closed 2023-02-22 · 76% similar
DigiCert: Non-BR-Compliant OCSP Responders
#1524730 RESOLVED Certificate Misissuance Revocation Issue Opened 2019-02-02 · Closed 2023-02-22 · 75% similar
Sectigo: invalid dnsName
#1575022 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2019-08-19 · Closed 2023-02-22 · 75% similar
Sectigo: EV SSL Certificates with incorrect subject details.
#1645686 RESOLVED Certificate Misissuance Revocation Issue Opened 2020-06-14 · Closed 2023-02-22 · 75% similar
Sectigo: Lack of input validation in stateOrProvinceName
#1590810 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-10-23 · Closed 2023-02-22 · 74% similar
Sectigo: EV SSL Certificates with incorrect businessCategory
#1653504 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-07-17 · Closed 2023-02-22 · 74% similar
Sectigo: Certificates with RSA keys where modulus is not divisible by 8

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action