Google Trust Services: Incorrect OCSP response for issued certificate
This case involves Google Trust Services (GTS) addressing an issue with incorrect OCSP responses for a newly issued certificate. The problem was initially reported by a user who received an 'unauthorized' response while validating a GTS-issued certificate for YouTube. GTS acknowledged the report and initiated an investigation, concluding that the unauthorized response was due to a temporary error during the OCSP query and not a compliance failure. GTS confirmed that the OCSP response was not for the currently served certificate but for a newly issued one that had not yet propagated globally. The CA has since implemented changes to improve OCSP response propagation times and confirmed that they can now provide OCSP services for all non-expired certificates issued by their primary CA platform.
- User reports an 'unauthorized' OCSP response for a GTS-issued certificate.
- GTS completes global deployment of changes to improve OCSP response propagation.
- Thisisntrocket representative — Reported an issue with GTS' OCSP responders returning 'unauthorized' responses.
- Google representative — Acknowledged the issue and initiated an incident response.
- Google representative — Confirmed GTS can now provide OCSP services for all non-expired certificates.