IdenTrust: Failure to provide OCSP responses for valid ICA certificates
IdenTrust reported that, during enhancements to its ICA monitoring, it discovered that the OCSP responder for its root CA “IdenTrust Commercial Root CA 1” returned “Unauthorized” status for three valid ICA certificates. The CA stated this was a violation of CA/B Forum Baseline Requirements section 4.10.2 requiring an online 24x7 repository for status of all unexpired certificates issued by the CA. IdenTrust investigated and determined the issue was due to a missed configuration step: the affected ICA certificates were not loaded into the production OCSP database. The CA then loaded the missing ICA certificates into the production OCSP database and confirmed that valid OCSP responses were being generated, resolving the immediate problem. IdenTrust also updated its ICA creation procedures with a post-configuration quality check and planned enhanced OCSP responder monitoring to test for valid responses for each ICA. The thread states that effective August 1, 2022, these OCSP responders were being monitored and that the CA considered the issue resolved; Mozilla indicated it would close the bug on 10-Aug-2022. The bug is marked RESOLVED with resolution FIXED.
- IdenTrust discovered that its OCSP responder was not providing valid status information for three valid ICA certificates under IdenTrust Commercial Root CA 1.
- IdenTrust confirmed the cause as missing configuration (ICAs not loaded into the production OCSP database) and then loaded the missing ICAs to restore valid OCSP responses.
- IdenTrust finalized a permanent resolution path and confirmed no other ICAs in scope had the issue.
- IdenTrust began monitoring the relevant OCSP responders and stated it considered the issue resolved.
- IdenTrust Services, LLC — IdenTrust disclosed that its OCSP responder returned “Unauthorized” for three valid ICA certificates and described the investigation, remediation (loading missing ICAs into the production OCSP database), and prevention steps.
- IdenTrust Services, LLC — IdenTrust reported the OCSP responder monitoring enhancement was on track and stated it would post another status update.
- IdenTrust Services, LLC — IdenTrust reiterated it was on track to deploy the monitoring enhancement and planned a further status update.
- IdenTrust Services, LLC — IdenTrust again stated it was on track to deploy the monitoring enhancement and planned another status update.
- IdenTrust Services, LLC — IdenTrust reported continued progress toward deploying the monitoring enhancement and planned a status update.
- IdenTrust Services, LLC — IdenTrust stated it was on track and planned another status update.
- IdenTrust Services, LLC — IdenTrust stated that effective August 1, 2022, the OCSP responders were being monitored and that it had no further actions and considered the issue resolved.
- Mozilla representative — Mozilla indicated it would close the bug on 10-Aug-2022 unless there were questions.