← Sectigo cases
Bugzilla #1763203
Certificate Problem Report
Sectigo: Incorrect OCSP responses
RESOLVED
FIXED
Sectigo
AI Summary
Sectigo was notified of incorrect OCSP responses affecting 294 certificates on March 22, 2022. The issue was traced to a CDN provider and was resolved by adjusting configurations, reducing the number of affected certificates to 65. No misissued certificates resulted from this incident. Sectigo has implemented monitoring scripts to prevent future occurrences and is awaiting the deployment of new OCSP code to fully remediate the issue.
Chronology
- Sectigo notified of incorrect OCSP responses.
- Sectigo provides detailed investigation report.
- Sectigo confirms readiness to close the case pending OCSP service deployment.
Participants
Martijn Katerbarg
Ryan Sleevi
Andrew Ayer
External References
Similar Local Cases
Sectigo: Failure to block disallowed LDH labels in domain names
Sectigo: Certificates with RSA keys where modulus is not divisible by 8
Sectigo: Mojibake in certificate Subject fields
Sectigo: Temporary failure to publish OCSP responses for newly issued certificates
Sectigo: Missing registration numbers in EV certificates
Sectigo: QWAC certificates issued with incorrect subject:organizationIdentifier attribute value
Sectigo: Intermittent OCSP unauthorized responses for certificates older than 15 minutes
Sectigo: OV reuse data applied for wrong organization