← HARICA cases
Bugzilla #1649945
Certificate Problem Report
HARICA: Incorrect OCSP Delegated Responder Certificate
RESOLVED
FIXED
HARICA
AI Summary
HARICA issued OCSP Delegated Responder certificates without the required `id-pkix-ocsp-nocheck` response, violating Baseline Requirements. The CA initiated an investigation upon discovering the issue, confirming that the affected certificates were never enabled to sign OCSP responses. HARICA developed a mitigation plan, which included revoking the affected certificates and destroying the associated keys. The incident was resolved with the completion of the key destruction ceremony, witnessed by an external auditor.
Chronology
- Initial report of the incident
- All remaining affected CAs were revoked and keys destroyed
Participants
Dimitris Zacharopoulos
Ryan Sleevi
External References
Similar Local Cases
HARICA: OCSP Responder Returned "Unauthorized" for Some Precertificates
GlobalSign: Incorrect OCSP Delegated Responder Certificate
HARICA: Insufficient serial number entropy
HARICA: Anomaly in OCSP services after CA software upgrade
Atos: Incorrect OCSP Delegated Responder Certificate
HARICA: Certificates with invalid policy tree
HARICA: wrong characters in NC extension of Technically Constrained Intermediate CA Certificates
HARICA: S/MIME certificate issuance without proper validation