Atos: Incorrect OCSP Delegated Responder Certificate (missing id-pkix-ocsp-nocheck)
The case concerns Atos OCSP Delegated Responder (ICA) certificates that were issued without including the `id-pkix-ocsp-nocheck` response, which the Baseline Requirements require. The issue was initially reported to m.d.s.p, and Atos then opened and investigated this Bugzilla case. Atos stated it started investigating the issue, and reported that it revoked affected CAs (2 of 4 first, then the remaining CAs) within seven days, with an incident report to follow. In its incident report response, Atos described how it became aware of the problem and provided a timeline, including customer notification and issuance of replacement CAs. Atos also stated that after 2020-03-17 it did not issue further ICAs using the `id-kp-OCSPSigning` EKU, and that all affected ICAs were revoked on 2020-07-07 and 2020-07-08. Later, Atos reported that the private keys of the affected ICAs were destroyed in the presence of its auditor on 2020-07-14, and that all affected ICAs had been revoked and keys destroyed. Mozilla indicated it could be closed unless additional questions or issues were raised.
- Atos began investigating the reported OCSP delegated responder certificate compliance issue and initiated the incident response in this Bugzilla case.
- Atos revoked two of four affected ICA certificates.
- Atos revoked the remaining affected ICA certificates.
- Atos destroyed the private keys of the affected ICA certificates in the presence of its auditor.
- Mozilla indicated the bug could be closed unless additional questions or issues were received.
- Community commenter — Reported that Atos issued OCSP Delegated Responders without the required `id-pkix-ocsp-nocheck` response and requested an incident report with a revocation timeline.
- Disabled representative — Said Atos started investigating and that more information would follow.
- Disabled representative — Reported revocation progress (2 of 4 first, remaining to be revoked the same day) and stated an incident report would follow by end of the week.
- Disabled representative — Provided a detailed incident report response including awareness, actions taken, affected certificate details, remediation steps, and future issuance changes.
- Mozilla representative — Asked for an update when key destruction was completed.
- Disabled representative — Reported that on 2020-07-14 the private keys of the affected ICAs were destroyed in the presence of the auditor, and that all affected ICAs were revoked and keys destroyed.
- Mozilla representative — Indicated the bug could be closed and would be queued for closure on or after 24-July-2020 unless further questions arose.