← IdenTrust Services, LLC cases
Bugzilla #1678410 Delayed Revocation

IdenTrust: Invalid OCSP Response Held in Cache

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

IdenTrust reported an OCSP validation problem affecting relying parties after it deployed a new OCSP signing certificate and new OCSP responses for certificates signed by DST Root CA X3. After uploading the new responses to its OCSP responder, the cache was not purged for the old response, and IdenTrust learned that its CDN cache could be held for up to 12 hours, extending beyond the expiration of the previous OCSP signing certificate. This caused errors validating OCSP responses for some relying parties of the Let’s Encrypt subordinate CAs that have been cross signed by DST Root CA X3, and there was also a period of about 30 minutes where external monitors reported outage due to excessive traffic overload. IdenTrust stated that issuance was not stopped for this incident and identified problematic OCSP signer expirations and the affected Let’s Encrypt Authority X3 and X4 certificates via crt.sh links. In follow-up, Mozilla asked about refinements to the remediation plan and whether remediations were implemented; IdenTrust agreed to a wording update and stated that no further refinements were needed and that remediation changes had been implemented, requesting closure. The bug is resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:13 UTC Revised: 2026-06-16 19:17 UTC Confidence: 0.50 3 comments
Chronology
  1. IdenTrust deployed a new OCSP signing certificate and uploaded new OCSP responses, but the CDN cache was not purged for the old response.
  2. The delegated OCSP signing certificate expired, leaving cached OCSP responses that could not validate for some relying parties until cache expiration.
  3. IdenTrust confirmed remediation changes were implemented and the issue could be closed.
Thread Activity
  1. IdenTrust Services, LLC — IdenTrust described the incident timeline: new OCSP responses were deployed without purging old cached responses, leading to OCSP validation errors and a brief outage due to traffic overload, and provided crt.sh links for the affected certificates.
  2. Mozilla representative — Mozilla asked whether the remediation plan should include contacting ISRG to manually clear the cache if the renewed certificate cannot be published within 24 hours, and whether all remediations were implemented.
  3. IdenTrust Services, LLC — IdenTrust accepted the suggested language update, stated no further refinements were needed, confirmed remediation changes were implemented, and said the matter could be closed.
Participants
IdenTrust Services, LLC Mozilla representative
Similar Local Cases
#1914067 RESOLVED Delayed Revocation Opened 2024-08-20 · Closed 2024-10-23 · 97% similar
IdenTrust: Expired CRLs
#1792111 RESOLVED Delayed Revocation Incident Opened 2022-09-22 · Closed 2023-02-22 · 96% similar
IdenTrust: Expired CRLs
#1870402 RESOLVED Delayed Revocation Opened 2023-12-15 · Closed 2024-06-30 · 95% similar
IdenTrust: Expired CRL served
#1736706 RESOLVED Delayed Revocation Opened 2021-10-19 · Closed 2023-02-22 · 95% similar
IdenTrust: Failure to Revoke Subscriber Certificates Within 5 days
#1853447 RESOLVED Delayed Revocation Opened 2023-09-15 · Closed 2023-10-12 · 94% similar
IdenTrust: Temporarily Expired CRLs
#1757247 RESOLVED Delayed Revocation Opened 2022-02-25 · Closed 2023-02-22 · 94% similar
IdenTrust: Delay Revocation for EV SSL Certificates
#1851710 RESOLVED Delayed Revocation Opened 2023-09-05 · Closed 2024-01-04 · 93% similar
IdenTrust: Delay beyond 5 days in revoking misissued certificates
#1656487 RESOLVED Delayed Revocation Opened 2020-07-31 · Closed 2023-02-22 · 70% similar
Izenpe: Failure to revoke within 5 days

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action