← DigiCert cases
Bugzilla #1733000 Certificate Misissuance

QuoVadis: revocation services validity set to expected value plus one second

RESOLVED FIXED DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The bug describes a timing issue affecting QuoVadis revocation services (OCSP and CRL) where the validity period was effectively set to the expected value plus one second. The CA said it became aware of the problem by following a bug posted by GTS (Bug 1731164) and that, on 9/24, GTS informed it that QuoVadis OCSP services were off by one second due to inclusive start time handling. The CA stated that QuoVadis OCSP responses are good for 48 hours, which is shorter than the requirement in Baseline Requirements section 4.9.10, and that because time is inclusive, OCSP responses set to 48 hours were actually valid for 48 hours and 1 second; the same was said to apply to CRL validity periods being 1 second longer than defined in the CPS. In response, the CA said it stopped issuing CRL and OCSP responses outside the timeline specified in the QuoVadis CPS and updated the QuoVadis CPS to accurately describe revocation services timing, with CPS approval and publication on 9/24. The CA also reported contacting PrimeKey to update EJBCA to account for the 1-second issue and referenced a planned EJBCA update (EJBCA 7.8.0.1) when available. The bug was resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:24 UTC Revised: 2026-06-16 18:51 UTC Confidence: 0.50 4 comments
Chronology
  1. GTS notified the CA that QuoVadis OCSP responses were off by one second due to inclusive start time handling.
  2. The CA updated and published the QuoVadis CPS to correct revocation services timing terminology.
  3. The CA stated the correction was to amend the CPS and noted planned EJBCA fixes via PrimeKey.
  4. Mozilla planned to close the matter on or about this date unless there were objections.
Thread Activity
  1. DigiCert — Explained how GTS informed the CA of the one-second OCSP timing issue, described the inclusive-time effect on OCSP/CRL validity versus CPS/BR terminology, and stated actions taken including stopping out-of-timeline issuance and updating the QuoVadis CPS.
  2. DigiCert — Added an attachment listing issuing CAs affected by the “plus second” on revocation services.
  3. DigiCert — Clarified that the correction was to amend CPS terminology, stated CRL/OCSP settings were within maximum validity periods in BR requirements, and referenced the PrimeKey EJBCA fix.
  4. Mozilla representative — Indicated intent to close the matter on or about 13-Oct-2021 unless there were objections.
Participants
DigiCert Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1645708 RESOLVED Certificate Misissuance Opened 2020-06-14 · Closed 2023-02-22 · 75% similar
QuoVadis: EV serialNumber with "none"
#1667518 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-09-26 · Closed 2023-02-22 · 67% similar
QuoVadis: Incorrect keyUsage for ECC certificate
#1904257 RESOLVED Certificate Misissuance Opened 2024-06-23 · Closed 2024-06-30 · 67% similar
Microsoft PKI Services: Invalid Email Address for CPRs
#1649947 RESOLVED Certificate Misissuance Opened 2020-07-02 · Closed 2023-02-22 · 67% similar
Microsec: Incorrect OCSP Delegated Responder Certificate
#1910451 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-07-29 · Closed 2024-08-21 · 66% similar
Sectigo: Missing character in subject:organizationName attribute value
#1710856 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-05-12 · Closed 2023-02-22 · 66% similar
DigiCert: Invalid localityName
#1705647 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-04-16 · Closed 2023-02-22 · 66% similar
KIR S.A.: Invalid organizationName
#1942130 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2025-01-16 · Closed 2025-05-01 · 66% similar
HARICA: S/MIME certificate issuance without proper validation

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action