KIR OCSP Unknown statuses for certificates generated but not yet delivered
This case concerns reports that many KIR certificates were showing OCSP status "Unknown" even though they had been issued or were otherwise present in CRLs. The bug was opened by a third party who cited crt.sh examples and KIR's CPS language defining "Unknown" as meaning a certificate was not issued by KIR. KIR explained that the affected certificates were generated but not yet delivered to end users, and said it would report the issue as an incident and implement technical changes so such certificates would be placed in OCSP. KIR later said it had deployed an OCSP/CRL sync change, completed a full scan, and found no certificates with OCSP Unknown. The thread also expanded into related questions about forward-dated certificates and CPS wording, and KIR said it had updated its CPS, stopped TLS issuance until the update took effect, and later stated that it no longer issues forward-dated certificates.
- Third-party report identified many KIR certificates with OCSP Unknown status.
- KIR said it would update its CPS, change TLS validity wording, and stop TLS issuance until the update took effect.
- KIR deployed an OCSP/CRL sync change and reported no certificates with OCSP Unknown after a full scan.
- KIR stated it no longer issues forward-dated certificates.
- Lebihan representative — Reported many certificates with OCSP Unknown and cited KIR CPS language saying Unknown means a certificate was not issued by KIR.
- Kir representative — Said KIR would report an incident and explained the issue involved certificates generated but not yet issued to users.
- Kir representative — Said KIR would scan all certificates, add unissued certificates to OCSP, and implement an automatic mechanism for doing so.
- Kir representative — Provided a bug report timeline and said the issue concerned OCSP and CRL status inconsistencies for certificates generated but not handed to users.
- Kir representative — Said KIR would update its CPS to make TLS validity 398 days from certificate generation and stop TLS issuance until the update was in force.
- Kir representative — Reported that the OCSP/CRL sync change was deployed, a full scan was run, and no certificate with OCSP Unknown was found.
- Kir representative — Stated that KIR no longer issues forward-dated certificates.
- Mozilla representative — Said the bug would be closed on or about 2021-07-14 unless there were additional questions.
- Kir representative — Asked whether the bug could be closed based on the prior notice.