← Apple Inc. cases
Bugzilla #1771398
Certificate Problem Report
Apple: OCSP responders return ‘unknown’ for valid S/MIME and TLS certificates
RESOLVED
FIXED
Apple Inc.
AI Summary
Apple's OCSP validation service was found to be returning 'unknown' instead of 'good' for valid S/MIME certificates, which violated their stated practices. The issue was identified on May 23, 2022, and was resolved the same day by updating the OCSP publisher configuration. Affected certificates were monitored, and no problematic certificates were issued in error. The CA has since implemented measures to ensure compliance with OCSP response standards.
Chronology
- Issue identified with OCSP responses for valid S/MIME certificates.
- OCSP publisher configuration updated to resolve the issue.
- Initial report filed detailing the incident and remediation steps.
- All lints are now run on every public certificate issued.
Participants
certification_authority@apple.com
External References
Similar Local Cases
Apple: OCSP responders return responses with incorrect issuer
Apple: Revocation Delay for TLS certificates issued outside the TTL of the CAA record
Apple: TLS certificates issued outside the TTL of the CAA record
Apple: Public Key Reuse
Apple: Test website certificates expired
Apple: EV Certificate Approver Authorization
Apple: CRLs for dormant CAs will not be populated in CCADB
Apple: OCSP availability 2020-11-12