DigiCert incorrect OCSP delegated responder certificate disclosure and revocation plan
This case concerns DigiCert’s disclosure that it had issued one or more OCSP Delegated Responder certificates without the required id-pkix-ocsp-nocheck response. The issue was first raised publicly on mozilla.dev.security.policy and then filed in Bugzilla by Ryan Sleevi. DigiCert acknowledged the report, investigated, and provided a timeline covering affected legacy issuing CAs and their planned or completed revocations and key destruction. Over the course of the thread, DigiCert reported revocation of some intermediates, scheduled destruction for others, and provided a detailed remediation plan for the Microsoft-related ICAs. The thread later focused on key-destruction evidence, auditor-witnessed reports, and whether the case could be closed once the remaining report was posted. The bug is marked RESOLVED/FIXED.
- A DigiCert OCSP delegated responder compliance issue was raised publicly on mozilla.dev.security.policy.
- The Bugzilla case was opened for DigiCert’s OCSP delegated responder certificate issue.
- VZ Cybertrust Client CA was revoked on schedule.
- Microsoft’s revocation occurred on schedule.
- Microsoft key-destruction documentation was posted.
- Community commenter — Ryan Sleevi reported that DigiCert had issued OCSP Delegated Responder certificates without the required id-pkix-ocsp-nocheck response and requested an incident report with a revocation timeline.
- Community commenter — DigiCert acknowledged the problem report and said it was investigating before posting a response.
- Community commenter — DigiCert described affected legacy ICAs, said it would not issue new certificates with the OCSP EKU, and outlined revocation and shutdown timelines for the impacted customers.
- Disabled representative — Microsoft provided a detailed remediation plan, including re-issuance, interim controls, and a timeline for key destruction of the four impacted Microsoft IT TLS CAs.
- Disabled representative — Microsoft explained interim controls for the impacted CAs and said it would provide a future timeline for how its publicly trusted CAs could meet BR key-destruction time periods.
- Community commenter — DigiCert reported that Bechtel had submitted an attestation, VZ had been revoked on schedule, ABB was revoked, and KPN and Microsoft were still on track.
- Community commenter — DigiCert said Bechtel’s key destruction had been witnessed by another Bechtel employee, Verizon had completed witnessed key destruction, ABB remained revoked, and KPN and Microsoft were still on timeline.
- Community commenter — DigiCert confirmed Microsoft’s revocation happened on schedule on February 16 and said the key-destruction audit/report was in progress.
- Mozilla representative — Mozilla said the issue could be closed once the report was received.
- Community commenter — DigiCert posted Microsoft’s witnessed key-destruction report and said this was the last action for the case.