Atos incorrect OCSP delegated responder certificates without id-pkix-ocsp-nocheck
Atos reported that it had issued four intermediate CA certificates used for OCSP delegation that included the id-kp-OCSPSigning EKU but did not include the required id-pkix-ocsp-nocheck response. Ryan Sleevi opened the bug after first raising the issue on mozilla.dev.security.policy and provided an example certificate. Atos said it investigated, informed customers, revoked the affected ICAs, and updated its ICA profile to remove the id-kp-OCSPSigning EKU for future issuance. Atos also stated that the private keys for the affected ICAs were destroyed in the presence of its auditor. Mozilla later indicated the bug could be closed, and the bug is resolved fixed.
- An affected ICA certificate was issued with id-kp-OCSPSigning EKU and no id-pkix-ocsp-nocheck.
- An affected ICA certificate was issued with id-kp-OCSPSigning EKU and no id-pkix-ocsp-nocheck.
- An affected ICA certificate was issued with id-kp-OCSPSigning EKU and no id-pkix-ocsp-nocheck.
- An affected ICA certificate was issued with id-kp-OCSPSigning EKU and no id-pkix-ocsp-nocheck.
- Atos revoked two affected ICAs.
- Atos revoked the remaining affected ICAs.
- Atos destroyed the private keys of the affected ICAs in the presence of its auditor.
- Community commenter — Ryan Sleevi reported that Atos had issued OCSP Delegated Responders without the required id-pkix-ocsp-nocheck response and asked for an incident report with a revocation timeline.
- Disabled representative — Atos said it had started investigating the issue and would provide more information.
- Disabled representative — Atos said it had revoked two of four affected ICAs and would revoke the remaining ones that day, with a detailed incident report to follow.
- Disabled representative — Atos provided an incident report describing discovery, timeline, affected certificates, root cause, and remediation steps.
- Mozilla representative — Mozilla asked for an update when key destruction had been completed.
- Disabled representative — Atos confirmed the private keys had been destroyed in the presence of its auditor and that all affected ICAs had been revoked.
- Mozilla representative — Mozilla said the bug could be closed and planned to close it unless further issues were raised.