IdenTrust: Invalid OCSP Response Held in Cache
IdenTrust reported an OCSP validation problem affecting relying parties after it deployed a new OCSP signing certificate and new OCSP responses for certificates signed by DST Root CA X3. After uploading the new responses to its OCSP responder, the cache was not purged for the old response, and IdenTrust learned that its CDN cache could be held for up to 12 hours, extending beyond the expiration of the previous OCSP signing certificate. This caused errors validating OCSP responses for some relying parties of the Let’s Encrypt subordinate CAs that have been cross signed by DST Root CA X3, and there was also a period of about 30 minutes where external monitors reported outage due to excessive traffic overload. IdenTrust stated that issuance was not stopped for this incident and identified problematic OCSP signer expirations and the affected Let’s Encrypt Authority X3 and X4 certificates via crt.sh links. In follow-up, Mozilla asked about refinements to the remediation plan and whether remediations were implemented; IdenTrust agreed to a wording update and stated that no further refinements were needed and that remediation changes had been implemented, requesting closure. The bug is resolved as FIXED.
- IdenTrust deployed a new OCSP signing certificate and uploaded new OCSP responses, but the CDN cache was not purged for the old response.
- The delegated OCSP signing certificate expired, leaving cached OCSP responses that could not validate for some relying parties until cache expiration.
- IdenTrust confirmed remediation changes were implemented and the issue could be closed.
- IdenTrust Services, LLC — IdenTrust described the incident timeline: new OCSP responses were deployed without purging old cached responses, leading to OCSP validation errors and a brief outage due to traffic overload, and provided crt.sh links for the affected certificates.
- Mozilla representative — Mozilla asked whether the remediation plan should include contacting ISRG to manually clear the cache if the renewed certificate cannot be published within 24 hours, and whether all remediations were implemented.
- IdenTrust Services, LLC — IdenTrust accepted the suggested language update, stated no further refinements were needed, confirmed remediation changes were implemented, and said the matter could be closed.