← SK ID Solutions AS cases
Bugzilla #1649942 Certificate Misissuance

SK ID Solutions: Incorrect OCSP Delegated Responder Certificate

RESOLVED FIXED SK ID Solutions AS
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns SK ID Solutions issuing one or more OCSP Delegated Responder certificates without including the `id-pkix-ocsp-nocheck` response, which the Baseline Requirements require. The issue was initially reported to Mozilla by Ryan Sleevi, and Kathleen Wilson assigned the bug to herself/others after noting that Bug 1621159 had set the CA to distrusted for TLS, which affected OCSP functioning for the intermediates. SK ID Solutions acknowledged the issue and provided an incident report dated 06.07.2020 describing internal investigation steps and an action plan. SK stated it would revoke (or let expire) the last valid end-entity TLS certificates and would prepare a risk assessment during week 28. Kathleen Wilson indicated Mozilla only had the Websites trust bit enabled for the root and referenced Bug 1651211 to remove the root certificate in the next NSS root changes. After Mozilla’s plan to remove the root via Bug 1651211, Kathleen Wilson said she was fine with closing this bug. The bug is resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:10 UTC Revised: 2026-06-16 18:32 UTC Confidence: 0.86 8 comments
Chronology
  1. Bug 1649942 was filed reporting that SK ID Solutions issued OCSP delegated responder certificates missing the required `id-pkix-ocsp-nocheck` response.
  2. SK ID Solutions produced an incident report describing awareness of the Bugzilla report and internal investigation and planned remediation.
  3. SK ID Solutions requested closure after completing a risk assessment and noting root removal via Bug 1651211.
Thread Activity
  1. Community commenter — Reported that SK ID Solutions issued OCSP Delegated Responders without the required `id-pkix-ocsp-nocheck` response and provided example and references to Baseline Requirements sections.
  2. Sk representative — Acknowledged the issue and started investigation/analysis.
  3. Sk representative — Posted an incident report dated 06.07.2020, listing awareness timing, internal review, affected CA certificates, and an action plan including revoking or letting expire the last valid end-entity TLS certificates and preparing a risk assessment.
  4. Mozilla representative — Explained Mozilla’s trust-bit situation and stated she filed Bug 1651211 to remove the root certificate; also agreed with letting end-entity TLS certificates expire.
  5. Sk representative — Asked for clarification on the timing of the September root changes referenced by Mozilla.
  6. Mozilla representative — Provided timing details for whether the September batch would land in NSS 3.57, mapping that to Firefox 82 or Firefox 83.
  7. Sk representative — Requested closure, stating SK had made a risk assessment and that root removal via Bug 1651211 was underway.
  8. Mozilla representative — Stated she was fine with closing the bug since the root certificate would be removed via Bug 1651211.
Participants
Community commenter Mozilla representative Sk representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1398243 RESOLVED Certificate Misissuance Opened 2017-09-08 · Closed 2023-02-22 · 78% similar
certSIGN: Non-BR-Compliant OCSP Responders
#1883843 RESOLVED Certificate Misissuance Opened 2024-03-06 · Closed 2024-08-13 · 70% similar
Entrust: EV TLS Certificate cPSuri missing
#1902748 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-06-14 · Closed 2026-06-10 · 69% similar
Sectigo: QWAC certificates issued with incorrect subject:organizationIdentifier attribute value
#1293366 RESOLVED Certificate Misissuance Opened 2016-08-08 · Closed 2022-11-14 · 69% similar
WoSign issued SHA-1 SSL certs and backdated the issuance date on SSL certificates
#1691704 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-02-09 · Closed 2023-02-22 · 69% similar
SwissSign: Certificate with key length 4098 bit
#1734131 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-10-05 · Closed 2023-02-22 · 69% similar
SwissSign: wrong address in EV certificate
#1676367 RESOLVED Certificate Misissuance Opened 2020-11-10 · Closed 2023-02-22 · 69% similar
NetLock: Issuance of >398-day precertificates after 2020-09-01
#1785865 RESOLVED Certificate Misissuance Opened 2022-08-18 · Closed 2024-05-09 · 69% similar
NAVER Cloud Trust Services: DV certificate issued with no subject alternative name extension

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action