← Apple Inc. cases
Bugzilla #1669618
Certificate Problem Report
Apple: Empty SingleExtension in OCSP responses
RESOLVED
FIXED
Apple Inc.
AI Summary
Apple identified an issue with their OCSP responses containing an empty SingleExtension, similar to a previously reported bug by GlobalSign. The problem was traced back to the version of EJBCA they were using, which exhibited non-compliant behavior. Apple took immediate action by investigating the issue, contacting the software provider, and implementing a fix by upgrading to a newer version of EJBCA. They also updated their OCSP lints and test cases to prevent future occurrences. The incident did not affect certificate issuance.
Chronology
- Identified potential impact from GlobalSign's report.
- Contacted PrimeKey regarding the issue.
- Deployed alpha version of EJBCA 7.4.3 and verified the fix.
- Completed all remediation tasks.
- Scheduled to close the bug.
Participants
Apple CA
Ryan Sleevi
B Wilson
External References
Similar Local Cases
Asseco DS / Certum: Incorrect localityName
Google Trust Services: Incorrect revocation data temporarily served for GTS Y3 & Y4
DigiCert / Microsoft: inconsistent disclosure of externally-operated intermediate
DigiCert: Apple: Non-compliant Serial Numbers
Izenpe: Failure to revoke within 5 days
Actalis: Failure to revoke within 7 days: OCSP EKU issue
Apple: Public Key Reuse
Apple: OCSP availability 2020-11-12