← DigiCert cases
Bugzilla #1649938 Self Reported Incident

QuoVadis: Incorrect OCSP Delegated Responder Certificate

RESOLVED FIXED DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

QuoVadis identified a compliance issue regarding the issuance of OCSP Delegated Responder certificates that did not include the required `id-pkix-ocsp-nocheck` response. This issue was initially reported in the Mozilla dev-security-policy mailing list. In response, QuoVadis initiated an investigation and outlined a remediation plan, which included revocation of affected sub CAs and the creation of new CAs without the compliance issue. The CA has been actively working on replacing and revoking certificates, with a completion target set for December 31, 2020. The case has been resolved with the necessary actions taken.

Model: gpt-4o-mini Generated: 2026-06-13 21:21 UTC Revised: 2026-06-16 18:50 UTC Confidence: 0.85 22 comments
Chronology
  1. QuoVadis acknowledged the issue and began investigating.
  2. QuoVadis provided a detailed timeline of actions taken in response to the issue.
  3. QuoVadis completed the revocation of affected CAs and key destruction.
Thread Activity
  1. Community commenter — Reported the issue regarding OCSP Delegated Responder certificates.
  2. DigiCert — Acknowledged the problem report and began investigation.
  3. DigiCert — Confirmed completion of revocation and key destruction for affected CAs.
Participants
Community commenter DigiCert
Similar Local Cases
#1581234 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-09-13 · Closed 2023-02-22 · 87% similar
QuoVadis: EV JOI Issue
#1579950 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-09-09 · Closed 2022-11-14 · 86% similar
QuoVadis: OCSP handling of Certificate Transparency Pre-certs
#1624504 RESOLVED Self Reported Incident Opened 2020-03-24 · Closed 2023-02-22 · 85% similar
QuoVadis: Failure to revoke certificates with compromised private keys
#1738472 RESOLVED Self Reported Incident Opened 2021-10-29 · Closed 2023-02-22 · 76% similar
QuoVadis: hostnames not in preferred name syntax
#1649944 RESOLVED Self Reported Incident Opened 2020-07-02 · Closed 2023-02-22 · 74% similar
Camerfirma: Incorrect OCSP Delegated Responder Certificate
#1649945 RESOLVED Self Reported Incident Opened 2020-07-02 · Closed 2023-02-22 · 73% similar
HARICA: Incorrect OCSP Delegated Responder Certificate
#1649964 RESOLVED Self Reported Incident Opened 2020-07-02 · Closed 2023-02-22 · 73% similar
PKIoverheid: Incorrect OCSP Delegated Responder Certificate
#1711147 RESOLVED Self Reported Incident Opened 2021-05-13 · Closed 2023-02-22 · 72% similar
Microsoft PKI Services: Malformed ICAs (missing certificate policy extensions)

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action