← Microsec Ltd. cases
Bugzilla #1649947 Certificate Misissuance

Microsec: Incorrect OCSP Delegated Responder Certificate

RESOLVED FIXED Microsec Ltd.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

A third party reported that Microsec issued one or more OCSP Delegated Responders without including the required id-pkix-ocsp-nocheck response, as required by the Baseline Requirements. The report included an example certificate and requested an incident report with a revocation timeline. Microsec confirmed receipt and investigated the issue, stating that the problematic certificate was a subordinate TSA CA certificate used to issue end-entity OCSP responder certificates for a delegated OCSP responder. Microsec described its investigation and risk assessment, including that it identified four ICA certificates issued with the same EKU-related problem and that it began setting up a plan to solve the security issue. Microsec also opened a separate incident report for late revocation of the TSA CA certificates (Bug 1651632). Mozilla closed this bug and directed further proceedings to Bug 1651632. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:12 UTC Revised: 2026-06-16 19:13 UTC Confidence: 0.86 9 comments
Chronology
  1. A report was filed alleging Microsec issued OCSP delegated responder-related certificates without the required id-pkix-ocsp-nocheck response.
  2. Microsec provided an incident report describing its investigation, risk assessment, and related findings.
  3. Microsec opened a separate incident report for late revocation of the TSA CA certificates (Bug 1651632).
  4. Mozilla closed this bug and pointed to Bug 1651632 for further proceedings.
Thread Activity
  1. Community commenter — Reported that Microsec issued OCSP Delegated Responders without id-pkix-ocsp-nocheck and requested an incident report with a revocation timeline.
  2. Microsec representative — Confirmed receipt of the report and stated Microsec was investigating the issue.
  3. Microsec representative — Submitted an incident report timeline, described the affected hierarchy and EKU behavior, and discussed a security risk assessment and remediation planning.
  4. Microsec representative — Noted that Microsec opened a separate incident report for late revocation of the TSA CA certificates (Bug 1651632).
  5. Microsec representative — Acknowledged that Microsec made a bad decision in 2019 and explained how it believes the issue was not recognized then.
  6. Mozilla representative — Willing to close this bug and consolidate further discussion under Bug 1651632; requested understanding of steps to follow relevant discussions.
  7. Microsec representative — Confirmed Microsec follows and occasionally participates in relevant CA incident and standards discussions, and said pending tasks would be shared in Bug 1651632.
  8. Mozilla representative — Closed this bug and directed readers to Bug 1651632 for further proceedings.
Participants
Community commenter Microsec representative Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1676352 RESOLVED Certificate Misissuance Incident Opened 2020-11-10 · Closed 2023-02-22 · 84% similar
Microsec: Certificate validity period greater than 398 days
#1645708 RESOLVED Certificate Misissuance Opened 2020-06-14 · Closed 2023-02-22 · 78% similar
QuoVadis: EV serialNumber with "none"
#1728384 RESOLVED Certificate Misissuance Incident Opened 2021-08-31 · Closed 2023-02-22 · 78% similar
Microsec: Misissuance of one OV certificate with Key Usage KeyEncipherment
#1886257 RESOLVED Certificate Misissuance Opened 2024-03-19 · Closed 2024-08-28 · 78% similar
Microsec: Misissuance an EV TLS certificate without CPSuri
#1710856 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-05-12 · Closed 2023-02-22 · 76% similar
DigiCert: Invalid localityName
#1717046 RESOLVED Certificate Misissuance Opened 2021-06-17 · Closed 2022-11-14 · 76% similar
Sectigo: potentially invalid organizational validation certificates
#1705647 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-04-16 · Closed 2023-02-22 · 75% similar
KIR S.A.: Invalid organizationName
#1910451 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-07-29 · Closed 2024-08-21 · 70% similar
Sectigo: Missing character in subject:organizationName attribute value

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action