← DigiCert cases
Bugzilla #1662346 Ca Security Vulnerability Security Incident

DigiCert: OCSP responder returning “good” for revoked certificates (on-demand OCSP)

RESOLVED FIXED DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

DigiCert reported that, while making system changes on 8/24/2020, it discovered a bug introduced on 7/22/2020 that caused its on-demand OCSP responder (ocspx.digicert.com) to return “good” for revoked certificates. DigiCert stated that the correct response was returned at ocsp.digicert.com and included in CRLs when the certificate included a CRL URI, but the AIA for affected certificates pointed to ocspx.digicert.com, so certificates had the wrong OCSP information. DigiCert investigated and determined that two issuing CAs were impacted, and it deployed a code fix on 8/27/2020 to send correct responses to both the on-demand and pre-signed services. DigiCert then moved remaining CAs to pre-signing only and shut down on-demand signing on 8/31/2020, stating that it had fixed the issue and finished shutting down on-demand signing. In the thread, Mozilla asked about the adequacy of pre-/post-deployment testing and systemic controls; DigiCert responded that it added acceptance automated tests for end-entity certificate status on the on-demand endpoint path and discussed expanding testing and PR process controls. DigiCert also described implementing PR templates and checklists to ensure major workflows are manually tested and/or automated on each PR, and indicated the process was implemented earlier than 10/15. The bug was resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 11:39 UTC Revised: 2026-06-16 19:05 UTC Confidence: 0.90 10 comments
Chronology
  1. A code change intended to migrate on-demand OCSP to pre-signed responses inadvertently included end-entity certificates.
  2. The CA began signing all responses as “good” for ocspx.digicert.com after deploying the change.
  3. DigiCert discovered the on-demand OCSP bug while planning shutdown steps for on-demand OCSP.
  4. DigiCert deployed a code fix to send correct responses to both on-demand and pre-signed OCSP services.
  5. DigiCert moved remaining CAs to pre-signing only and shut down on-demand signing.
Thread Activity
  1. Community commenter — Opened the bug with an incident timeline describing how on-demand OCSP returned “good” for revoked certificates and how DigiCert fixed the issue and shut down on-demand signing.
  2. DigiCert — Asked what additional information Mozilla wanted and stated DigiCert had turned off its on-demand signing service for TLS.
  3. Mozilla representative — Questioned whether more thorough pre- or post-deployment testing should be included to prevent similar incidents.
  4. Community commenter — Expressed concern that the response focused on incident-specific plans rather than systemic root causes and remediation.
  5. DigiCert — Explained the issue was noticed during routine sprint planning for shutting down the system and described added acceptance tests and testing expectations for workflow changes.
  6. Community commenter — Pressed for robust controls beyond testing, including how issues with test development would be detected.
  7. DigiCert — Said independent developer review missed the impact on end-entity certificates and described additional process improvements, including PR templates and checklists.
  8. DigiCert — Outlined a plan to implement PR templates/checklists and improve visibility and workflow testing across CA services, targeting completion by Oct 15.
  9. DigiCert — Reported that PR templates were implemented earlier than Oct 15 and were being used in CA-related code repositories.
  10. Mozilla representative — Scheduled the bug for closure on or about 16-October-2020 unless additional questions remained.
Participants
Community commenter DigiCert Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1577014 RESOLVED Security Incident Opened 2019-08-27 · Closed 2023-02-22 · 100% similar
DigiCert: OCSP services returns 1 byte
#1675684 RESOLVED Ca Security Vulnerability Security Incident Opened 2020-11-06 · Closed 2023-02-22 · 100% similar
DigiCert: Private Keys Disclosed by Customers as Part of CSR
#1744795 RESOLVED Ca Security Vulnerability Security Incident Opened 2021-12-07 · Closed 2023-02-22 · 100% similar
DigiCert: Issuance of certs with weak keys (ROCA)
#1816806 RESOLVED Ca Security Vulnerability Security Incident Opened 2023-02-15 · Closed 2023-03-09 · 100% similar
DigiCert: OCSP not responding issue
#1820269 RESOLVED Ca Security Vulnerability Security Incident Opened 2023-03-03 · Closed 2024-06-30 · 89% similar
DigiCert: 4 CRLs unavailable or not responding
#1878106 RESOLVED Ca Security Vulnerability Security Incident Opened 2024-02-01 · Closed 2024-03-08 · 79% similar
HARICA: Anomaly in OCSP services after CA software upgrade
#1424305 RESOLVED Ca Security Vulnerability Incident Opened 2017-12-08 · Closed 2023-02-22 · 78% similar
DigiCert: Microsoft: Incident report for Microsoft Dynamics incident
#1427034 RESOLVED Ca Security Vulnerability Security Incident Opened 2017-12-25 · Closed 2024-05-09 · 77% similar
DigiCert: localbattle.net certificate with private key in software / issued by Digicert

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action