← Apple Inc. cases
Bugzilla #1677234
Incident
Apple: OCSP availability 2020-11-12
RESOLVED
FIXED
Apple Inc.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
On November 12, 2020, Apple CA experienced diminished availability of its OCSP services due to issues with its CDN. The CA team was alerted to the problem at 12:46 PT and confirmed the CDN as the cause. They engaged with the CDN provider to implement mitigations, and by 13:43 PT, service availability had returned to normal. Apple CA reported that this incident did not affect certificate issuance, and they have since enhanced their monitoring and are implementing a solution to utilize third-party CDNs to prevent future issues. The incident was resolved with all tasks completed by January 30, 2021.
Chronology
- Apple CA experienced diminished OCSP service availability due to CDN issues.
- Apple CA completed tasks to enhance monitoring and implement third-party CDN solutions.
Thread Activity
- Apple representative — Apple’s OCSP services experienced diminished availability on November 12, 2020.
- Apple representative — Apple CA provided a full incident report detailing the timeline and actions taken.
- Apple representative — Apple CA confirmed completion of monitoring enhancements and third-party CDN implementation.
- Mozilla representative — Scheduled to close the case unless additional issues arise.
Participants
Apple representative
Community commenter
Mozilla representative
External References
Similar Local Cases
Apple: EV Certificate Approver Authorization
Apple: Empty SingleExtension in OCSP responses
Apple: Intermediate CA certificates omitted from audit statement
Apple: OCSP responders return ‘unknown’ for valid S/MIME and TLS certificates
Apple: CRL issuance frequency deviates from CPS in some cases
Apple: Test website certificates expired
Apple: CRLs for dormant CAs will not be populated in CCADB
E-Tugra: Forbidden Domain Validation Method 3.2.2.4.6