DigiCert delayed publication of OCSP revocation information due to origin-server push bug
This case concerned DigiCert’s delayed publication of revocation information for OCSP responses. It was opened after an external reporter observed that several certificates revoked by DigiCert were still returning valid "Good" OCSP responses more than 24 hours after the problem report had been received. DigiCert explained its revocation pipeline, investigated the delay, and later identified a bug in code handling revocations by serial number that prevented some revoked responses from being pushed to the origin server immediately. DigiCert said it fixed the bug, stopped serving delayed revocation responses, and added monitoring to track revocation through the system. The thread then focused on clarifying DigiCert’s incident report and the monitoring it had put in place before the bug was eventually closed.
- Several DigiCert certificates were revoked, but OCSP responses continued to return "Good" for longer than expected.
- An external report documented delayed availability of revoked OCSP responses for DigiCert certificates.
- DigiCert identified a bug affecting revocations by serial number and said it had fixed the delay.
- DigiCert described its OCSP batch, delivery, and monitoring flow in more detail.
- The discussion ended with no further questions from Mozilla.
- Hezmatt representative — Reported that DigiCert OCSP responders were still serving valid "Good" responses for revoked certificates well after the problem reports were received.
- DigiCert — Described DigiCert’s revocation process and said the observed delay was outside the expected range and under investigation.
- Community commenter — Questioned DigiCert’s use of CDN caching and whether the responses were actually being published to relying parties.
- DigiCert — Said DigiCert found a bug where revocations by serial number were not pushed to the origin server until the next batch and that the bug had been fixed.
- DigiCert — Said DigiCert needed monitoring that followed revocation through to the endpoint and estimated the work would take about two weeks once prioritized.
- DigiCert — Provided a detailed description of DigiCert’s OCSP generation, delivery, and monitoring components, and said it still lacked a timer for revocation-to-CDN availability.
- Community commenter — Said there were no further questions.