← Apple Inc. cases
Bugzilla #1771398
Incident
Apple: OCSP responders return ‘unknown’ for valid S/MIME and TLS certificates
RESOLVED
FIXED
Apple Inc.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
On May 23, 2022, Apple CA discovered that its OCSP validation service was incorrectly responding 'unknown' for valid S/MIME certificates, which violated its stated practices. The issue was identified internally, and Apple CA took immediate action to resolve it by updating the OCSP publisher configuration. The problem was fixed on the same day, and a full report was promised by June 9, 2022. Further investigation revealed a similar issue affecting one TLS certificate, which was also resolved. Apple CA has since implemented monitoring and remediation measures to prevent future occurrences.
Chronology
- Apple CA identified OCSP responses returning 'unknown' for valid S/MIME certificates.
- Apple CA resolved a similar issue for one TLS certificate.
Thread Activity
- Apple representative — Filed the Bugzilla and posted the initial issue report.
- Apple representative — Promised a full report regarding the OCSP issue.
- Apple representative — Confirmed that all lints are now run on every public certificate issued.
Participants
Apple representative
Mozilla representative
External References
Similar Local Cases
Apple: OCSP availability 2020-11-12
Apple: EV Certificate Approver Authorization
Apple: Test website certificates expired
Apple: Empty SingleExtension in OCSP responses
Apple: CRLs for dormant CAs will not be populated in CCADB
Apple: Intermediate CA certificates omitted from audit statement
Apple: CRL issuance frequency deviates from CPS in some cases
DigiCert: Domain used for CRLs and OCSP has expired