SK ID Solutions: Incorrect OCSP Delegated Responder Certificate
This case concerns SK ID Solutions issuing one or more OCSP Delegated Responder certificates without including the `id-pkix-ocsp-nocheck` response, which the Baseline Requirements require. The issue was initially reported to Mozilla by Ryan Sleevi, and Kathleen Wilson assigned the bug to herself/others after noting that Bug 1621159 had set the CA to distrusted for TLS, which affected OCSP functioning for the intermediates. SK ID Solutions acknowledged the issue and provided an incident report dated 06.07.2020 describing internal investigation steps and an action plan. SK stated it would revoke (or let expire) the last valid end-entity TLS certificates and would prepare a risk assessment during week 28. Kathleen Wilson indicated Mozilla only had the Websites trust bit enabled for the root and referenced Bug 1651211 to remove the root certificate in the next NSS root changes. After Mozilla’s plan to remove the root via Bug 1651211, Kathleen Wilson said she was fine with closing this bug. The bug is resolved as FIXED.
- Bug 1649942 was filed reporting that SK ID Solutions issued OCSP delegated responder certificates missing the required `id-pkix-ocsp-nocheck` response.
- SK ID Solutions produced an incident report describing awareness of the Bugzilla report and internal investigation and planned remediation.
- SK ID Solutions requested closure after completing a risk assessment and noting root removal via Bug 1651211.
- Community commenter — Reported that SK ID Solutions issued OCSP Delegated Responders without the required `id-pkix-ocsp-nocheck` response and provided example and references to Baseline Requirements sections.
- Sk representative — Acknowledged the issue and started investigation/analysis.
- Sk representative — Posted an incident report dated 06.07.2020, listing awareness timing, internal review, affected CA certificates, and an action plan including revoking or letting expire the last valid end-entity TLS certificates and preparing a risk assessment.
- Mozilla representative — Explained Mozilla’s trust-bit situation and stated she filed Bug 1651211 to remove the root certificate; also agreed with letting end-entity TLS certificates expire.
- Sk representative — Asked for clarification on the timing of the September root changes referenced by Mozilla.
- Mozilla representative — Provided timing details for whether the September batch would land in NSS 3.57, mapping that to Firefox 82 or Firefox 83.
- Sk representative — Requested closure, stating SK had made a risk assessment and that root removal via Bug 1651211 was underway.
- Mozilla representative — Stated she was fine with closing the bug since the root certificate would be removed via Bug 1651211.