← Eviden cases
Bugzilla #1649963
Certificate Problem Report
Atos: Incorrect OCSP Delegated Responder Certificate
RESOLVED
FIXED
Eviden
AI Summary
Atos issued OCSP Delegated Responder certificates without the required `id-pkix-ocsp-nocheck` response, violating Baseline Requirements. The issue was reported on July 2, 2020, leading to an investigation and subsequent revocation of affected certificates. All affected CAs were revoked within a week, and the private keys were destroyed in the presence of an auditor. An incident report detailing the timeline and corrective actions was provided.
Chronology
- Issue reported and investigation initiated.
- Revocation of 2 affected CAs.
- Private keys of affected ICAs destroyed.
Participants
Ryan Sleevi
u636358
External References
Similar Local Cases
GlobalSign: Incorrect OCSP Delegated Responder Certificate
DigiCert: Incorrect OCSP Delegated Responder Certificate
HARICA: Incorrect OCSP Delegated Responder Certificate
SECOM: Incorrect OCSP Delegated Responder Certificate
SK ID Solutions: Incorrect OCSP Delegated Responder Certificate
PKIoverheid: Incorrect OCSP Delegated Responder Certificate
Firmaprofesional: Incorrect OCSP Delegated Responder Certificate
Disig: Non-BR-Compliant OCSP Responders