← Atos cases
Bugzilla #1649963 Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Revocation Issue

Atos incorrect OCSP delegated responder certificates without id-pkix-ocsp-nocheck

RESOLVED FIXED Atos
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Atos reported that it had issued four intermediate CA certificates used for OCSP delegation that included the id-kp-OCSPSigning EKU but did not include the required id-pkix-ocsp-nocheck response. Ryan Sleevi opened the bug after first raising the issue on mozilla.dev.security.policy and provided an example certificate. Atos said it investigated, informed customers, revoked the affected ICAs, and updated its ICA profile to remove the id-kp-OCSPSigning EKU for future issuance. Atos also stated that the private keys for the affected ICAs were destroyed in the presence of its auditor. Mozilla later indicated the bug could be closed, and the bug is resolved fixed.

Model: gpt-5.4-mini Generated: 2026-09-06 11:09 UTC Confidence: 0.97 7 comments
Chronology
  1. An affected ICA certificate was issued with id-kp-OCSPSigning EKU and no id-pkix-ocsp-nocheck.
  2. An affected ICA certificate was issued with id-kp-OCSPSigning EKU and no id-pkix-ocsp-nocheck.
  3. An affected ICA certificate was issued with id-kp-OCSPSigning EKU and no id-pkix-ocsp-nocheck.
  4. An affected ICA certificate was issued with id-kp-OCSPSigning EKU and no id-pkix-ocsp-nocheck.
  5. Atos revoked two affected ICAs.
  6. Atos revoked the remaining affected ICAs.
  7. Atos destroyed the private keys of the affected ICAs in the presence of its auditor.
Thread Activity
  1. Community commenter — Ryan Sleevi reported that Atos had issued OCSP Delegated Responders without the required id-pkix-ocsp-nocheck response and asked for an incident report with a revocation timeline.
  2. Disabled representative — Atos said it had started investigating the issue and would provide more information.
  3. Disabled representative — Atos said it had revoked two of four affected ICAs and would revoke the remaining ones that day, with a detailed incident report to follow.
  4. Disabled representative — Atos provided an incident report describing discovery, timeline, affected certificates, root cause, and remediation steps.
  5. Mozilla representative — Mozilla asked for an update when key destruction had been completed.
  6. Disabled representative — Atos confirmed the private keys had been destroyed in the presence of its auditor and that all affected ICAs had been revoked.
  7. Mozilla representative — Mozilla said the bug could be closed and planned to close it unless further issues were raised.
Participants
Community commenter Disabled representative Mozilla representative
Similar Local Cases
#1540961 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Linting Quality Issue Opened 2019-04-02 · Closed 2023-02-22 · 97% similar
Atos: Insufficient Serial Number Entropy
#1649963 RESOLVED Self Reported Incident Opened 2020-07-02 · Closed 2023-02-22 · 94% similar
Atos: Incorrect OCSP Delegated Responder Certificate
#1649951 RESOLVED Self Reported Incident Revocation Issue Opened 2020-07-02 · Closed 2023-02-22 · 93% similar
DigiCert: Incorrect OCSP Delegated Responder Certificate
#1741026 RESOLVED Ca Certificate Compliance Revocation Issue Self Reported Incident Opened 2021-11-13 · Closed 2023-02-22 · 88% similar
Sectigo: Incorrect JOI for federal credit unions
#1650910 RESOLVED Self Reported Incident Audit Finding Revocation Issue Opened 2020-07-06 · Closed 2023-02-22 · 88% similar
DigiCert: Inconsistent EV audits
#1662382 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2020-09-01 · Closed 2023-02-22 · 88% similar
GDCA: Incorrect Value in organizationName Field
#1627346 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Delayed Revocation Opened 2020-04-03 · Closed 2023-02-22 · 88% similar
Entrust: S/MIME Certificate Issued with Incorrect Policy OID
#1717357 RESOLVED Certificate Misissuance Incident Opened 2021-06-20 · Closed 2023-02-22 · 88% similar
Actalis: Issuance of intermediates after 2020-08-20 that do not comply with Mozilla Policy and the Baseline Requirements

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action