← IdenTrust Services, LLC cases
Bugzilla #1758027
Certificate Problem Report
IdenTrust: Pre-certificates without a final certificate showing OCSP error
RESOLVED
FIXED
IdenTrust Services, LLC
AI Summary
IdenTrust identified a significant issue involving 4,667 pre-certificates that were issued without corresponding final certificates, leading to unauthorized OCSP responses. The problem was discovered during an internal review on February 23, 2022. IdenTrust has since taken steps to remediate the issue, including updating their TLS issuance process to ensure all pre-certificates are registered in the OCSP database, regardless of whether a final certificate is issued. The issue has been resolved as of May 23, 2022, following the deployment of a permanent solution.
Chronology
- Discovered pre-certificates with OCSP discrepancies.
- Implemented monitoring utility for pre-certificates.
- Deployed permanent solution to register pre-certificates in OCSP DB.
- Confirmed resolution of the issue.
Participants
IdenTrust
Mozilla
External References
Similar Local Cases
IdenTrust: Failure to provide OCSP responses for valid ICA certificates
IdenTrust: TLS self audit testing below 3%
IdenTrust: Expired CRLs
IdenTrust: Certificate with missing details flagged by OCSP Watch
IdenTrust: TLS ICA with User Notice in Policy Qualifier
IdenTrust: Bad OCSP Responses
IdenTrust: CRL Potential Publication Delay due to Cache
IdenTrust: Unavailable CRL for IdenTrust ‘DST Root CA X3’.