E-Tugra: Intermittent OCSP responses with status 'Unknown'
The case reports that the E-Tugra OCSP responder returned an OCSP response status of 'Unknown' intermittently for a certificate (referenced via crt.sh). The issue was noticed by Matias, who created the bug after observing the incorrect OCSP response status in a browser and attempting (unsuccessfully) to reproduce it via OpenSSL. E-Tugra stated that it received the bug on 19 Jan 2021 and fixed the problem on 19 Jan 2021 16:00 (GMT), then investigated whether the issue related to another Mozilla bug (1687139) and searched for other affected certificates. E-Tugra reported that it found no additional certificates with the same OCSP 'Unknown' behavior and said it did not stop issuing certificates or other CA functionalities. E-Tugra attributed the cause to certificates not being published to one of its OCSP servers in a globally load-balanced setup, and said an error format was not included in its SIEM systems to generate an alarm. As remediation, E-Tugra upgraded SIEM alarm rules for errors in the certificate issuing system and developed a Quality Control component to check OCSP results compatibility across OCSP servers after certificate changes; it was integrated with SIEM and put into production on 12 Feb. Mozilla indicated the incident could be closed and scheduled closure for 7-Apr-2021; the bug is resolved as FIXED.
- OCSP responder intermittently returned status 'Unknown' for an E-Tugra certificate observed via browser/OCSP checks.
- E-Tugra fixed the OCSP 'Unknown' problem and began detailed investigation and searching for other affected certificates.
- E-Tugra’s new Quality Control component for OCSP compatibility checks was put into production.
- Mozilla scheduled closure of the incident.
- Thisisntrocket representative — Created the bug after observing the OCSP responder returning status 'Unknown' for an E-Tugra certificate and noted it seemed incorrect.
- E-Tugra — Provided a preliminary report describing when E-Tugra received the bug, stated the problem was fixed on 19 Jan 2021 16:00, and described investigation, SIEM/OCSP server cause, and planned remediation.
- E-Tugra — Submitted additional details including the cause (certificate not published to one OCSP server) and remediation steps (SIEM rule upgrade and Quality Control component).
- Community commenter — Asked whether the expected end-of-week remediation was completed.
- E-Tugra — Reported that the Quality Control component was completed, integrated with SIEM, and put into production on 12 Feb.
- Mozilla representative — Indicated the incident could be closed and scheduled closure for 7-Apr-2021.