IdenTrust: OCSP Responder missing id-pkix-ocsp-nocheck
IdenTrust reported that it became aware of a compliance issue affecting a delegated OCSP signing certificate, specifically that the certificate was missing the id-pkix-ocsp-nocheck extension. The CA said it first learned of the problem on 2020-07-14 via an email sent to Mozilla’s certificate problem report public address. IdenTrust confirmed non-compliance with Baseline Requirements (BR) 4.9.9 (2) and stated that an update to the OCSP responders on 2020-06-23 caused the discrepancy. IdenTrust placed back the previously BR-compliant delegated OCSP signing certificate on the same day the issue was reported, and it stated that it had one delegated OCSP signing certificate with validity from 2020-06-24 to 2020-07-24. The thread also notes that IdenTrust delayed completing the formal Incident Report, expecting completion by 2020-07-28. In response to questions, IdenTrust described its OCSP signing key and certificate lifecycle at a high level, including key generation in FIPS-compliant HSMs and dual-control storage and deployment processes. The bug was resolved as FIXED, and Mozilla indicated an intent to close it on 2020-09-14 unless further questions or concerns remained.
- IdenTrust updated OCSP responders in a way that resulted in the delegated OCSP signing certificate missing the id-pkix-ocsp-nocheck extension.
- IdenTrust became aware of the missing id-pkix-ocsp-nocheck extension and restored the previously BR-compliant delegated OCSP signing certificate.
- IdenTrust created an attachment containing the incident report details.
- Mozilla indicated it intended to close the bug on 2020-09-14 unless additional questions or concerns were raised.
- IdenTrust Services, LLC — IdenTrust reported that it had resolved the missing id-pkix-ocsp-nocheck extension issue on the same day it was discovered and said it would provide a formal Incident report by 2020-07-24.
- IdenTrust Services, LLC — IdenTrust stated it was delayed in completing the Incident Report and expected to finish by 2020-07-28.
- IdenTrust Services, LLC — IdenTrust attached incident report information describing how it became aware of the problem, its timeline, the BR non-compliance, and remediation steps.
- Community commenter — Ryan Sleevi asked for more details about IdenTrust’s OCSP responder certificate/key lifecycle and key management, referencing RFC 6960 concerns.
- IdenTrust Services, LLC — IdenTrust provided a high-level description of its OCSP signing key generation, storage, chain of custody, and deployment process, including the EUP approach.
- Community commenter — Ryan Sleevi expressed unease about whether OCSP signing keys used for revocation could be stored on the same HSM as other keys, and noted a root revocation would be the step if that scenario occurred.
- Mozilla representative — Mozilla stated it intended to close the bug on 2020-09-14 unless there were additional questions or concerns.