← DigiCert cases
Bugzilla #1649951
Certificate Problem Report
DigiCert: Incorrect OCSP Delegated Responder Certificate
RESOLVED
DigiCert
AI Summary
DigiCert was reported for issuing OCSP Delegated Responder certificates without the required 'id-pkix-ocsp-nocheck' response, violating Baseline Requirements. The issue was acknowledged, and DigiCert provided a timeline for revocation of affected certificates. They committed to not issuing new certificates with the problematic OCSP EKU and outlined a detailed remediation plan, including customer notifications and revocation timelines for various intermediates.
Chronology
- Issue reported on Mozilla mailing list.
- Bug created in Bugzilla.
- Revocation of VZ Cybertrust Client CA completed.
- Revocation of Microsoft IT TLS CAs completed.
Participants
Ryan Sleevi
Martin Sullivan
Jeremy Rowley
External References
Similar Local Cases
DigiCert: OCSP responder returning invalid responses
DigiCert: & character in a printableString in ICA
DigiCert: Underscores - Discover
DigiCert: TI Trust Technologies Global CA issued certificate with no subject alternative name extension
DigiCert / Microsoft: inconsistent disclosure of externally-operated intermediate
DigiCert: Failure to revoke key-compromised certificate
DigiCert: Issuance of Cert with Compromised Key
DigiCert: JOI Issue