← IdenTrust Services, LLC cases
Bugzilla #1653680 Self Incident Disclosure

IdenTrust: OCSP Responder missing id-pkix-ocsp-nocheck

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

IdenTrust reported that it became aware of a compliance issue affecting a delegated OCSP signing certificate, specifically that the certificate was missing the id-pkix-ocsp-nocheck extension. The CA said it first learned of the problem on 2020-07-14 via an email sent to Mozilla’s certificate problem report public address. IdenTrust confirmed non-compliance with Baseline Requirements (BR) 4.9.9 (2) and stated that an update to the OCSP responders on 2020-06-23 caused the discrepancy. IdenTrust placed back the previously BR-compliant delegated OCSP signing certificate on the same day the issue was reported, and it stated that it had one delegated OCSP signing certificate with validity from 2020-06-24 to 2020-07-24. The thread also notes that IdenTrust delayed completing the formal Incident Report, expecting completion by 2020-07-28. In response to questions, IdenTrust described its OCSP signing key and certificate lifecycle at a high level, including key generation in FIPS-compliant HSMs and dual-control storage and deployment processes. The bug was resolved as FIXED, and Mozilla indicated an intent to close it on 2020-09-14 unless further questions or concerns remained.

Model: gpt-5.4-nano Generated: 2026-06-13 21:12 UTC Revised: 2026-06-16 19:16 UTC Confidence: 0.86 8 comments
Chronology
  1. IdenTrust updated OCSP responders in a way that resulted in the delegated OCSP signing certificate missing the id-pkix-ocsp-nocheck extension.
  2. IdenTrust became aware of the missing id-pkix-ocsp-nocheck extension and restored the previously BR-compliant delegated OCSP signing certificate.
  3. IdenTrust created an attachment containing the incident report details.
  4. Mozilla indicated it intended to close the bug on 2020-09-14 unless additional questions or concerns were raised.
Thread Activity
  1. IdenTrust Services, LLC — IdenTrust reported that it had resolved the missing id-pkix-ocsp-nocheck extension issue on the same day it was discovered and said it would provide a formal Incident report by 2020-07-24.
  2. IdenTrust Services, LLC — IdenTrust stated it was delayed in completing the Incident Report and expected to finish by 2020-07-28.
  3. IdenTrust Services, LLC — IdenTrust attached incident report information describing how it became aware of the problem, its timeline, the BR non-compliance, and remediation steps.
  4. Community commenter — Ryan Sleevi asked for more details about IdenTrust’s OCSP responder certificate/key lifecycle and key management, referencing RFC 6960 concerns.
  5. IdenTrust Services, LLC — IdenTrust provided a high-level description of its OCSP signing key generation, storage, chain of custody, and deployment process, including the EUP approach.
  6. Community commenter — Ryan Sleevi expressed unease about whether OCSP signing keys used for revocation could be stored on the same HSM as other keys, and noted a root revocation would be the step if that scenario occurred.
  7. Mozilla representative — Mozilla stated it intended to close the bug on 2020-09-14 unless there were additional questions or concerns.
Participants
IdenTrust Services, LLC Community commenter Mozilla representative
Similar Local Cases
#1709192 RESOLVED Incident Opened 2021-05-03 · Closed 2023-02-22 · 68% similar
IdenTrust: Unavailable CRL for IdenTrust ‘DST Root CA X3’.
#1718552 RESOLVED Certificate Misissuance Opened 2021-06-28 · Closed 2023-02-22 · 68% similar
IdenTrust: Certificates with Invalid values for stateOrProvinceName
#1744627 RESOLVED Ca Certificate Compliance Opened 2021-12-06 · Closed 2023-02-22 · 68% similar
IdenTrust: Issuance of OV SSL Certificate with doc vetting older than 398 days
#1749089 RESOLVED Ca Certificate Compliance Opened 2022-01-08 · Closed 2023-02-22 · 68% similar
IdenTrust: OCSP Signer Certificate Missing No-Check Extension
#1598807 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-11-23 · Closed 2023-02-22 · 67% similar
IdenTrust: Undisclosed Unrevoked ICAs
#1753287 RESOLVED Incident Opened 2022-02-02 · Closed 2024-07-08 · 67% similar
IdenTrust: Validation Source for EV Certificates not Publicly Disclosed
#1663080 RESOLVED Certificate Misissuance Opened 2020-09-03 · Closed 2023-02-22 · 66% similar
IdenTrust: Issuance of certificates greater than 398 days
#1758027 RESOLVED Self Incident Disclosure Opened 2022-03-04 · Closed 2023-02-22 · 63% similar
IdenTrust: Pre-certificates without a final certificate showing OCSP error

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action