← Sectigo cases
Bugzilla #1763203 Ca Certificate Compliance Incident Self Reported Incident Revocation Issue Remediation Tracking

Sectigo incident report on incorrect OCSP responses

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo opened this bug to notify Mozilla and the community that it had been notified of incorrect OCSP responses from its OCSP servers. Sectigo said it first learned of the issue from a message by Andrew Ayer on m.d.s.p. and began investigating immediately. In its follow-up, Sectigo reported three root causes, including a CDN-related problem affecting one OCSP host and an OCSP response generation issue for certificates whose precertificates had been issued but whose final certificates were never issued. Sectigo stated that the incident did not lead to any misissued certificates. The company described remediation steps including CDN configuration changes, additional monitoring, and deployment of new OCSP code, and later said the remaining remediation depended on that deployment tracked in Bug 1741777. The bug was resolved FIXED.

Model: gpt-5.4-mini Generated: 2026-06-13 20:57 UTC Revised: 2026-06-28 05:16 UTC Confidence: 0.95 14 comments
Chronology
  1. Sectigo was notified of incorrect OCSP responses from its OCSP servers.
  2. CDN configuration changes reduced the number of affected certificates and resolved the malformed OCSP responses.
  3. Sectigo identified three root causes for the problematic OCSP responses and described remediation steps.
  4. Sectigo said the only remaining factor was deployment of its new OCSP service, tracked in Bug 1741777.
  5. Sectigo said progress updates would continue in Bug 1741777.
Thread Activity
  1. Sectigo — Sectigo said it was aware of the incident and would post a full response within seven days.
  2. Sectigo — Sectigo provided a timeline, said it found 294 affected certificates, and explained the first two root causes.
  3. Sectigo — Sectigo noted that the OCSP gap between precertificate issuance and valid OCSP responses was a non-compliance concern and said it was working to reduce the gap.
  4. Sectigo — Sectigo said remediation and closure depended on deployment of new OCSP code tracked in Bug 1741777.
  5. Mozilla representative — Mozilla asked whether the bug could be closed on 20-May-2022 or whether issues remained dependent on work in Bug 1741777.
  6. Sectigo — Sectigo said the only remaining factor was deployment of the new OCSP service and agreed the bug could be closed while progress continued in Bug 1741777.
Participants
Sectigo Community commenter Thisisntrocket representative Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1740493 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-11-10 · Closed 2023-02-22 · 100% similar
Sectigo: Failure to block disallowed LDH labels in domain names
#1741026 RESOLVED Ca Certificate Compliance Revocation Issue Self Reported Incident Opened 2021-11-13 · Closed 2023-02-22 · 100% similar
Sectigo: Incorrect JOI for federal credit unions
#1563579 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-07-04 · Closed 2023-02-22 · 100% similar
Sectigo: Failure to provide timely incident reports
#1593776 RESOLVED Ca Certificate Compliance Incident Opened 2019-11-04 · Closed 2023-02-22 · 100% similar
Sectigo: invalid subject:organizationalUnitName on DV certificates
#1650845 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-07-06 · Closed 2024-06-30 · 100% similar
Sectigo: CPR response issues
#1718771 RESOLVED Self Reported Incident Revocation Issue Opened 2021-06-30 · Closed 2023-02-22 · 100% similar
Sectigo: DCV Reuse after 825 days
#1575022 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2019-08-19 · Closed 2023-02-22 · 96% similar
Sectigo: EV SSL Certificates with incorrect subject details.
#1793787 RESOLVED Ca Certificate Compliance Self Reported Incident Incident Repository Issue Opened 2022-10-05 · Closed 2023-02-22 · 95% similar
Sectigo: Non-existent hostname in CDP and AIA URLs

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action