Microsec: Incorrect OCSP Delegated Responder Certificate
A third party reported that Microsec issued one or more OCSP Delegated Responders without including the required id-pkix-ocsp-nocheck response, as required by the Baseline Requirements. The report included an example certificate and requested an incident report with a revocation timeline. Microsec confirmed receipt and investigated the issue, stating that the problematic certificate was a subordinate TSA CA certificate used to issue end-entity OCSP responder certificates for a delegated OCSP responder. Microsec described its investigation and risk assessment, including that it identified four ICA certificates issued with the same EKU-related problem and that it began setting up a plan to solve the security issue. Microsec also opened a separate incident report for late revocation of the TSA CA certificates (Bug 1651632). Mozilla closed this bug and directed further proceedings to Bug 1651632. The bug is marked RESOLVED with resolution FIXED.
- A report was filed alleging Microsec issued OCSP delegated responder-related certificates without the required id-pkix-ocsp-nocheck response.
- Microsec provided an incident report describing its investigation, risk assessment, and related findings.
- Microsec opened a separate incident report for late revocation of the TSA CA certificates (Bug 1651632).
- Mozilla closed this bug and pointed to Bug 1651632 for further proceedings.
- Community commenter — Reported that Microsec issued OCSP Delegated Responders without id-pkix-ocsp-nocheck and requested an incident report with a revocation timeline.
- Microsec representative — Confirmed receipt of the report and stated Microsec was investigating the issue.
- Microsec representative — Submitted an incident report timeline, described the affected hierarchy and EKU behavior, and discussed a security risk assessment and remediation planning.
- Microsec representative — Noted that Microsec opened a separate incident report for late revocation of the TSA CA certificates (Bug 1651632).
- Microsec representative — Acknowledged that Microsec made a bad decision in 2019 and explained how it believes the issue was not recognized then.
- Mozilla representative — Willing to close this bug and consolidate further discussion under Bug 1651632; requested understanding of steps to follow relevant discussions.
- Microsec representative — Confirmed Microsec follows and occasionally participates in relevant CA incident and standards discussions, and said pending tasks would be shared in Bug 1651632.
- Mozilla representative — Closed this bug and directed readers to Bug 1651632 for further proceedings.