← Microsec Ltd. cases
Bugzilla #1649947
Certificate Problem Report
Microsec: Incorrect OCSP Delegated Responder Certificate
RESOLVED
FIXED
Microsec Ltd.
AI Summary
Microsec Ltd. faced an issue regarding the issuance of OCSP Delegated Responder certificates that did not comply with the Baseline Requirements. The problem was reported on July 2, 2020, leading to an investigation by Microsec. They confirmed that the certificates in question were technically constrained and intended for specific uses, but acknowledged the risk of misuse due to the lack of proper EKU chaining. The case was resolved with Microsec committing to improve their compliance and monitoring practices.
Chronology
- Problem reported to Microsec regarding OCSP Delegated Responder certificates.
- Microsec provided a detailed incident report outlining their investigation and actions taken.
- Bug closed with a recommendation to refer to related Bug #1651632 for further proceedings.
Participants
Ryan Sleevi
Dr. Sándor SZŐKE
B. Wilson
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
Microsec: "DV valid" test website certificate issued under incorrect root
Microsec: Inconsistent Disclosure of S/MIME BR Audit Information in CCADB
Microsec: Disallowed subject attribute field in DV certificate
e-commerce monitoring GmbH: Revoked test website not using revoked certificate
MICROSEC: Incident report - No OCSP status response for 2 Precertificates
Microsec: Late response to a CPR
Sectigo: EV SSL Certificates with incorrect businessCategory
Microsec: Issuance of 2 IVCP precertificates without givenName, surName, localityName fields