← Certainly LLC cases
Bugzilla #1771238 Incident

Certainly: Serving Expired OCSP Responses

RESOLVED FIXED Certainly LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Certainly reported that it became aware of an OCSP problem where its OCSP service was serving expired responses. It stated that the OCSP updater process that periodically generates new OCSP responses for existing certificates had been failing since 17-May 2022, and that during annual audit evidence gathering it found some returned OCSP responses were expired. Certainly investigated and declared an incident on 24-May 2022, determining the issue was likely caused by a configuration change related to the latest Boulder release; it also reported that reverting the configuration did not immediately resolve the problem. On 25-May 2022, Certainly rolled back Boulder to a prior release in production and deployed a fix so that OCSP response generation resumed, and it reported the service was fully restored once new OCSP responses were generated for all non-expired certificates. The thread also documents remediation actions, including upgrades and fixes to startup/monitoring behavior, pre-release OCSP testing, and implementing stale OCSP response alerts and external OCSP monitors. The bug was resolved as FIXED, and Mozilla indicated it would close the case on or about 5-Aug-2022 after remediation completion.

Model: gpt-5.4-nano Generated: 2026-06-13 21:26 UTC Revised: 2026-06-16 18:17 UTC Confidence: 0.88 9 comments
Chronology
  1. OCSP updater service began panicking and became unable to sign fresh OCSP responses.
  2. Incident was declared after expired OCSP responses were found during investigation.
  3. Production was rolled back and OCSP response generation was restored for non-expired certificates.
  4. All planned remediation tasks were reported as completed.
Thread Activity
  1. Fastly representative — Reported that Certainly discovered it was serving expired OCSP responses, provided a timeline, and stated production was rolled back and service restored after new OCSP responses were generated.
  2. Fastly representative — Explained how the CA became aware (annual audit evidence), described the actions taken, and provided root-cause details and affected certificate count (~10,647).
  3. Internet Security Research Group — Asked for more detail on the root-cause explanation and suggested adding safety checks and a Boulder PR.
  4. Fastly representative — Confirmed the analysis matched Certainly’s understanding and stated it would submit a Boulder PR, referencing issue #6150.
  5. Fastly representative — Requested a next update (23-June) and described alerting improvements, including catch-all alerts for panics and Boulder errors.
  6. Fastly representative — Provided a remediation plan status table, noting some items were done and others delayed (e.g., stale OCSP response alerts).
  7. Fastly representative — Updated remediation progress, stating remaining tasks were on track and requesting a next update for 30-July.
  8. Fastly representative — Reported that all planned remediation tasks for the incident were completed.
  9. Mozilla representative — Stated Mozilla would close the bug on or about 5-Aug-2022.
Participants
Fastly representative Internet Security Research Group Mozilla representative
External References
Similar Local Cases
#1798053 RESOLVED Incident Opened 2022-10-28 · Closed 2023-02-22 · 99% similar
Certainly: Serving Bad OCSP Responses
#1968836 RESOLVED Incident Self Reported Incident Opened 2025-05-28 · Closed 2025-08-26 · 79% similar
Certainly: Sample Websites Unavailable
#1905446 RESOLVED Incident Opened 2024-06-28 · Closed 2024-12-09 · 77% similar
IdenTrust: Unauthorized OCSP response on a Timestamp certificate
#1772644 RESOLVED Incident Opened 2022-06-04 · Closed 2023-02-22 · 76% similar
Apple: CRL issuance frequency deviates from CPS in some cases
#1751984 RESOLVED Incident Self Reported Incident Opened 2022-01-25 · Closed 2023-02-22 · 72% similar
Let's Encrypt: TLS Using ALPN TLS Version and OID
#2052399 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Repository Issue Opened 2026-07-03 Still Open · 70% similar
Certainly: Expired certificates on "Valid" and "Revoked" test websites
#2052085 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Audit Finding Opened 2026-07-02 Still Open · 70% similar
Certainly: Missing audit log entries for certificates issued during capacity testing
#1902310 RESOLVED Incident Opened 2024-06-13 · Closed 2024-07-11 · 69% similar
Sectigo: Trusted Role Access provided prior to completion of onboarding process

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action