← IdenTrust Services, LLC cases
Bugzilla #1678410
Certificate Problem Report
IdenTrust: Invalid OCSP Response Held in Cache
RESOLVED
FIXED
IdenTrust Services, LLC
AI Summary
IdenTrust experienced an issue where an invalid OCSP response was held in cache after deploying a new OCSP signing certificate. This led to validation errors for some relying parties of Let's Encrypt subordinate CAs cross-signed by DST Root CA X3. The problem was identified on October 16, 2020, when connectivity alerts were triggered due to excessive traffic overload, resulting in a temporary outage. The cache issue persisted until the old responses expired, which could have affected clients during that time. IdenTrust has since implemented remediation steps to prevent recurrence.
Chronology
- New OCSP response signed, old response cached
- Delegated OCSP signing certificate expired
- Connectivity alert issued
Participants
IdenTrust
External References
Similar Local Cases
IdenTrust: CA Certificate not published in DER Encoded Format
IdenTrust: Certificate with missing details flagged by OCSP Watch
IdenTrust: Temporarily Expired CRLs
IdenTrust: Bad OCSP Responses
IdenTrust: Certificates with Invalid values for stateOrProvinceName
IdenTrust: Incorrect Subject Details for HydrantId
IdenTrust: OCSP Outage
IdenTrust: Test Certificates from cross-signed roots not disclosed in CT Logs