Sectigo incident report on incorrect OCSP responses
Sectigo opened this bug to notify Mozilla and the community that it had been notified of incorrect OCSP responses from its OCSP servers. Sectigo said it first learned of the issue from a message by Andrew Ayer on m.d.s.p. and began investigating immediately. In its follow-up, Sectigo reported three root causes, including a CDN-related problem affecting one OCSP host and an OCSP response generation issue for certificates whose precertificates had been issued but whose final certificates were never issued. Sectigo stated that the incident did not lead to any misissued certificates. The company described remediation steps including CDN configuration changes, additional monitoring, and deployment of new OCSP code, and later said the remaining remediation depended on that deployment tracked in Bug 1741777. The bug was resolved FIXED.
- Sectigo was notified of incorrect OCSP responses from its OCSP servers.
- CDN configuration changes reduced the number of affected certificates and resolved the malformed OCSP responses.
- Sectigo identified three root causes for the problematic OCSP responses and described remediation steps.
- Sectigo said the only remaining factor was deployment of its new OCSP service, tracked in Bug 1741777.
- Sectigo said progress updates would continue in Bug 1741777.
- Sectigo — Sectigo said it was aware of the incident and would post a full response within seven days.
- Sectigo — Sectigo provided a timeline, said it found 294 affected certificates, and explained the first two root causes.
- Sectigo — Sectigo noted that the OCSP gap between precertificate issuance and valid OCSP responses was a non-compliance concern and said it was working to reduce the gap.
- Sectigo — Sectigo said remediation and closure depended on deployment of new OCSP code tracked in Bug 1741777.
- Mozilla representative — Mozilla asked whether the bug could be closed on 20-May-2022 or whether issues remained dependent on work in Bug 1741777.
- Sectigo — Sectigo said the only remaining factor was deployment of the new OCSP service and agreed the bug could be closed while progress continued in Bug 1741777.