DigiCert: OCSP responder returning “good” for revoked certificates (on-demand OCSP)
DigiCert reported that, while making system changes on 8/24/2020, it discovered a bug introduced on 7/22/2020 that caused its on-demand OCSP responder (ocspx.digicert.com) to return “good” for revoked certificates. DigiCert stated that the correct response was returned at ocsp.digicert.com and included in CRLs when the certificate included a CRL URI, but the AIA for affected certificates pointed to ocspx.digicert.com, so certificates had the wrong OCSP information. DigiCert investigated and determined that two issuing CAs were impacted, and it deployed a code fix on 8/27/2020 to send correct responses to both the on-demand and pre-signed services. DigiCert then moved remaining CAs to pre-signing only and shut down on-demand signing on 8/31/2020, stating that it had fixed the issue and finished shutting down on-demand signing. In the thread, Mozilla asked about the adequacy of pre-/post-deployment testing and systemic controls; DigiCert responded that it added acceptance automated tests for end-entity certificate status on the on-demand endpoint path and discussed expanding testing and PR process controls. DigiCert also described implementing PR templates and checklists to ensure major workflows are manually tested and/or automated on each PR, and indicated the process was implemented earlier than 10/15. The bug was resolved as FIXED.
- A code change intended to migrate on-demand OCSP to pre-signed responses inadvertently included end-entity certificates.
- The CA began signing all responses as “good” for ocspx.digicert.com after deploying the change.
- DigiCert discovered the on-demand OCSP bug while planning shutdown steps for on-demand OCSP.
- DigiCert deployed a code fix to send correct responses to both on-demand and pre-signed OCSP services.
- DigiCert moved remaining CAs to pre-signing only and shut down on-demand signing.
- Community commenter — Opened the bug with an incident timeline describing how on-demand OCSP returned “good” for revoked certificates and how DigiCert fixed the issue and shut down on-demand signing.
- DigiCert — Asked what additional information Mozilla wanted and stated DigiCert had turned off its on-demand signing service for TLS.
- Mozilla representative — Questioned whether more thorough pre- or post-deployment testing should be included to prevent similar incidents.
- Community commenter — Expressed concern that the response focused on incident-specific plans rather than systemic root causes and remediation.
- DigiCert — Explained the issue was noticed during routine sprint planning for shutting down the system and described added acceptance tests and testing expectations for workflow changes.
- Community commenter — Pressed for robust controls beyond testing, including how issues with test development would be detected.
- DigiCert — Said independent developer review missed the impact on end-entity certificates and described additional process improvements, including PR templates and checklists.
- DigiCert — Outlined a plan to implement PR templates/checklists and improve visibility and workflow testing across CA services, targeting completion by Oct 15.
- DigiCert — Reported that PR templates were implemented earlier than Oct 15 and were being used in CA-related code repositories.
- Mozilla representative — Scheduled the bug for closure on or about 16-October-2020 unless additional questions remained.