IdenTrust: Pre-certificates without a final certificate showing OCSP error
IdenTrust reported an internal compliance issue involving pre-certificates for which no final certificate was issued, resulting in OCSP responses of "unauthorized". During an internal review, IdenTrust found 4,543 such pre-certificates and later identified an additional 124, for 4,667 unexpired pre-certificates issued between 2021-04-07 and 2022-03-11. IdenTrust stated that these pre-certificates were submitted to CT logs and that its OCSP responders returned "unauthorized" because the pre-certificates were not registered in the OCSP database when the final certificate was not issued. IdenTrust said it violated CA/B Forum Baseline Requirements section 4.10.2 and Mozilla recommended practice for handling pre-certificates. In response, IdenTrust registered the identified pre-certificates in the OCSP DB and confirmed valid OCSP responses for each pre-certificate, and it deployed a permanent fix by updating the TLS issuance process to register each pre-certificate into the OCSP DB regardless of whether a final certificate will be issued. IdenTrust stated that it successfully deployed the solution and considered the issue resolved on 2022-05-23, and Mozilla indicated it would close the bug on or about 2022-05-27 unless further questions arose.
- IdenTrust began issuing pre-certificates that later were found to lack corresponding final certificates and OCSP entries.
- IdenTrust discovered pre-certificates with missing OCSP status entries during an internal review.
- IdenTrust put in place a monitoring utility to check every 24 hours for pre-certificates missing a final certificate and remediate OCSP status.
- IdenTrust planned and then deployed the permanent fix to register pre-certificates in the OCSP DB regardless of final certificate issuance.
- IdenTrust reported the permanent solution was successfully deployed and considered the issue resolved.
- IdenTrust Services, LLC — IdenTrust reported that internal review found 4,543 pre-certificates with "unauthorized" OCSP responses where no final certificate was issued, and said it was investigating and would supply a full incident report.
- IdenTrust Services, LLC — IdenTrust said it had made progress updating the abandoned pre-certificates to reflect valid OCSP status and would post the complete incident report by 2022-03-15.
- IdenTrust Services, LLC — IdenTrust provided the incident report details, including discovery of 4,667 cases, the "unauthorized" OCSP responses, the stated Baseline Requirements violation, and remediation and prevention steps.
- IdenTrust Services, LLC — IdenTrust attached an Excel file listing the problematic pre-certificates.
- IdenTrust Services, LLC — IdenTrust stated that as of 2022-03-16 it had a monitoring utility checking every 24 hours for pre-certificates missing a final certificate and remediating OCSP status.
- IdenTrust Services, LLC — IdenTrust reported the permanent solution was in QA testing and expected to be in production by 2022-05-23.
- IdenTrust Services, LLC — IdenTrust said it was on track to deploy the permanent solution on 2022-05-21 and would post a status update by 2022-05-23.
- IdenTrust Services, LLC — IdenTrust stated it successfully deployed the solution and considered the issue resolved.
- Mozilla representative — Mozilla indicated it would close the bug on or about 2022-05-27 unless there were additional questions or issues.