← Google Trust Services LLC cases
Bugzilla #1678183 Certificate Problem Report

Google Trust Services: Invalid ASN.1 encoding of singleExtensions in OCSP responses

RESOLVED FIXED Google Trust Services LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Google Trust Services reported that it received a notification from PrimeKey about an EJBCA update that included fixes for compliance-related issues affecting one Google Trust Services CA. The issue described was that an empty SEQUENCE could be included when no singleExtensions exist for a SingleResponse in OCSP responses. Google stated that the bug was introduced by the software vendor and that it had not received reports from user agents failing to validate the affected OCSP responses. Google confirmed the issue and remediated it by rolling out the updated EJBCA version to its test environment and then to production, and it stated that no problematic certificates were issued. In response to questions about quality checks, Google said its primary checks include zlint, internal test suites, and use of openssl asn1parse to check encodings, along with probers that cover validity and correctness of OCSP responses. Mozilla staff indicated the bug would be scheduled for closure after no further follow-up questions were apparent, and the bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:23 UTC Revised: 2026-06-16 18:38 UTC Confidence: 0.50 10 comments
Chronology
  1. Google updated the affected EJBCA installation from version 7.2.1 to 7.3.1, which included the issue.
  2. Google received a PrimeKey notification about an EJBCA version that included fixes for the OCSP singleExtensions encoding issue.
  3. Google rolled out the updated EJBCA version to the production environment to remediate the issue.
Thread Activity
  1. Google representative — Opened the incident report describing the OCSP ASN.1 encoding issue, stating no problematic certificates were issued and that remediation occurred via EJBCA update rollout.
  2. Community commenter — Asked whether Google monitors Bugzilla incident reports from other CAs and requested more detail on the quality checks and whether they match GlobalSign’s approach.
  3. Community commenter — Noted that Apple was also affected in a separate bug and that Apple’s resolution steps had similar detail to GlobalSign’s.
  4. Google representative — Explained that Google monitors m.d.s.p posts and Bugzilla incident reports, described investigation timing, and listed quality checks including zlint, internal test suites, openssl asn1parse, and OCSP probers.
  5. Community commenter — Raised concerns about the level of detail in the incident report and questioned the described quality checks and root-cause framing.
  6. Google representative — Responded with clarification requests about weekly updates expectations, described prioritization and onboarding steps, and acknowledged that it does not perform a before/after ASN.1 diff for OCSP responses.
  7. Google representative — Stated it was unclear whether weekly updates are expected for issues pending responses and said Google was awaiting feedback.
  8. Mozilla representative — Said it did not appear there were follow-up questions and scheduled the bug to be closed on or about 16-April-2021.
  9. Mozilla representative — Thanked commenters for suggestions for going forward.
Participants
Google representative Community commenter Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1809864 RESOLVED Certificate Misissuance Opened 2023-01-12 · Closed 2024-05-09 · 52% similar
Google Trust Services: Mis-issued certificates for citi.com subdomain due to lack of CAA record checking
#1634795 RESOLVED Revocation Issue Delayed Revocation Opened 2020-05-01 · Closed 2023-02-22 · 50% similar
Google Trust Services: Incorrect revocation data temporarily served for GTS Y3 & Y4
#1652581 RESOLVED Ca Certificate Compliance Opened 2020-07-13 · Closed 2023-02-22 · 50% similar
Google Trust Services: digitalSignature KeyUsage not set
#1706967 RESOLVED Self Incident Disclosure Opened 2021-04-22 · Closed 2023-02-22 · 49% similar
Google Trust Services: Forbidden Domain Validation Method 3.2.2.4.10
#1708516 RESOLVED Incident Opened 2021-04-29 · Closed 2023-02-22 · 49% similar
Google Trust Services: Failure to provide regular and timely incident updates
#1648717 RESOLVED Certificate Problem Report Opened 2020-06-26 · Closed 2023-02-22 · 48% similar
Sectigo: Failure to provide a preliminary report within 24 hours.
#1630040 RESOLVED Self Reported Incident Opened 2020-04-14 · Closed 2023-02-22 · 42% similar
Google Trust Services: OCSP serving issue 2020-04-09
#1717046 RESOLVED Certificate Misissuance Opened 2021-06-17 · Closed 2022-11-14 · 41% similar
Sectigo: potentially invalid organizational validation certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action