← Krajowa Izba Rozliczeniowa S.A. (KIR) cases
Bugzilla #1705657 Ca Certificate Compliance Revocation Issue

KIR OCSP Unknown statuses for certificates generated but not yet delivered

RESOLVED FIXED Krajowa Izba Rozliczeniowa S.A. (KIR)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns reports that many KIR certificates were showing OCSP status "Unknown" even though they had been issued or were otherwise present in CRLs. The bug was opened by a third party who cited crt.sh examples and KIR's CPS language defining "Unknown" as meaning a certificate was not issued by KIR. KIR explained that the affected certificates were generated but not yet delivered to end users, and said it would report the issue as an incident and implement technical changes so such certificates would be placed in OCSP. KIR later said it had deployed an OCSP/CRL sync change, completed a full scan, and found no certificates with OCSP Unknown. The thread also expanded into related questions about forward-dated certificates and CPS wording, and KIR said it had updated its CPS, stopped TLS issuance until the update took effect, and later stated that it no longer issues forward-dated certificates.

Model: gpt-5.4-mini Generated: 2026-06-13 21:12 UTC Revised: 2026-06-16 17:29 UTC Confidence: 0.93 66 comments
Chronology
  1. Third-party report identified many KIR certificates with OCSP Unknown status.
  2. KIR said it would update its CPS, change TLS validity wording, and stop TLS issuance until the update took effect.
  3. KIR deployed an OCSP/CRL sync change and reported no certificates with OCSP Unknown after a full scan.
  4. KIR stated it no longer issues forward-dated certificates.
Thread Activity
  1. Lebihan representative — Reported many certificates with OCSP Unknown and cited KIR CPS language saying Unknown means a certificate was not issued by KIR.
  2. Kir representative — Said KIR would report an incident and explained the issue involved certificates generated but not yet issued to users.
  3. Kir representative — Said KIR would scan all certificates, add unissued certificates to OCSP, and implement an automatic mechanism for doing so.
  4. Kir representative — Provided a bug report timeline and said the issue concerned OCSP and CRL status inconsistencies for certificates generated but not handed to users.
  5. Kir representative — Said KIR would update its CPS to make TLS validity 398 days from certificate generation and stop TLS issuance until the update was in force.
  6. Kir representative — Reported that the OCSP/CRL sync change was deployed, a full scan was run, and no certificate with OCSP Unknown was found.
  7. Kir representative — Stated that KIR no longer issues forward-dated certificates.
  8. Mozilla representative — Said the bug would be closed on or about 2021-07-14 unless there were additional questions.
  9. Kir representative — Asked whether the bug could be closed based on the prior notice.
Participants
Lebihan representative Kir representative Community commenter Thisisntrocket representative Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1705647 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-04-16 · Closed 2023-02-22 · 100% similar
KIR S.A.: Invalid organizationName
#1532112 RESOLVED Ca Certificate Compliance Opened 2019-03-03 · Closed 2023-02-22 · 95% similar
KIR S.A.: O > 64 characters
#1705187 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-04-14 · Closed 2023-02-22 · 86% similar
KIR S.A.: CN domain not in SAN
#1710856 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-05-12 · Closed 2023-02-22 · 82% similar
DigiCert: Invalid localityName
#1815534 RESOLVED Ca Certificate Compliance Certificate Misissuance Revocation Issue Opened 2023-02-07 · Closed 2024-04-17 · 78% similar
e-commerce monitoring GmbH: SCT in precertificate
#2049237 ASSIGNED Ca Certificate Compliance Incident Externally Reported Incident Revocation Issue Opened 2026-06-22 Still Open · 76% similar
HARICA: Continued issuance and refusal to revoke TLS certificates for EU-sanctioned blocked entities (Sberbank, VTB, KAMAZ, ANO Dialog)
#1942270 RESOLVED Revocation Issue Repository Issue Opened 2025-01-17 · Closed 2025-04-07 · 74% similar
SSL.com: Revocation process requires submission to a form that is unusable
#1675923 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-11-07 · Closed 2024-05-09 · 73% similar
DigiCert: TERENA: Insufficient validation of organizationalUnitName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action