Google Trust Services: Invalid ASN.1 encoding of singleExtensions in OCSP responses
Google Trust Services reported that it received a notification from PrimeKey about an EJBCA update that included fixes for compliance-related issues affecting one Google Trust Services CA. The issue described was that an empty SEQUENCE could be included when no singleExtensions exist for a SingleResponse in OCSP responses. Google stated that the bug was introduced by the software vendor and that it had not received reports from user agents failing to validate the affected OCSP responses. Google confirmed the issue and remediated it by rolling out the updated EJBCA version to its test environment and then to production, and it stated that no problematic certificates were issued. In response to questions about quality checks, Google said its primary checks include zlint, internal test suites, and use of openssl asn1parse to check encodings, along with probers that cover validity and correctness of OCSP responses. Mozilla staff indicated the bug would be scheduled for closure after no further follow-up questions were apparent, and the bug is marked RESOLVED with resolution FIXED.
- Google updated the affected EJBCA installation from version 7.2.1 to 7.3.1, which included the issue.
- Google received a PrimeKey notification about an EJBCA version that included fixes for the OCSP singleExtensions encoding issue.
- Google rolled out the updated EJBCA version to the production environment to remediate the issue.
- Google representative — Opened the incident report describing the OCSP ASN.1 encoding issue, stating no problematic certificates were issued and that remediation occurred via EJBCA update rollout.
- Community commenter — Asked whether Google monitors Bugzilla incident reports from other CAs and requested more detail on the quality checks and whether they match GlobalSign’s approach.
- Community commenter — Noted that Apple was also affected in a separate bug and that Apple’s resolution steps had similar detail to GlobalSign’s.
- Google representative — Explained that Google monitors m.d.s.p posts and Bugzilla incident reports, described investigation timing, and listed quality checks including zlint, internal test suites, openssl asn1parse, and OCSP probers.
- Community commenter — Raised concerns about the level of detail in the incident report and questioned the described quality checks and root-cause framing.
- Google representative — Responded with clarification requests about weekly updates expectations, described prioritization and onboarding steps, and acknowledged that it does not perform a before/after ASN.1 diff for OCSP responses.
- Google representative — Stated it was unclear whether weekly updates are expected for issues pending responses and said Google was awaiting feedback.
- Mozilla representative — Said it did not appear there were follow-up questions and scheduled the bug to be closed on or about 16-April-2021.
- Mozilla representative — Thanked commenters for suggestions for going forward.