QuoVadis: Incorrect OCSP Delegated Responder Certificate
QuoVadis identified a compliance issue regarding the issuance of OCSP Delegated Responder certificates that did not include the required `id-pkix-ocsp-nocheck` response. This issue was initially reported in the Mozilla dev-security-policy mailing list. In response, QuoVadis initiated an investigation and outlined a remediation plan, which included revocation of affected sub CAs and the creation of new CAs without the compliance issue. The CA has been actively working on replacing and revoking certificates, with a completion target set for December 31, 2020. The case has been resolved with the necessary actions taken.
- QuoVadis acknowledged the issue and began investigating.
- QuoVadis provided a detailed timeline of actions taken in response to the issue.
- QuoVadis completed the revocation of affected CAs and key destruction.
- Community commenter — Reported the issue regarding OCSP Delegated Responder certificates.
- DigiCert — Acknowledged the problem report and began investigation.
- DigiCert — Confirmed completion of revocation and key destruction for affected CAs.