← Google Trust Services LLC cases
Bugzilla #1771552 Technical Compliance

Google Trust Services: OCSP responses not published in a timely manner

RESOLVED FIXED Google Trust Services LLC
AI Summary

Google Trust Services identified an issue with their OCSP responders where the `max-age` directive in the `Cache-Control` HTTP response header was set too high, potentially delaying the publication of updated OCSP responses. Following a thorough investigation, they implemented a series of changes to reduce the `max-age` value from 24 hours to 4 hours, significantly improving the timeliness of OCSP status updates. The issue did not result in certificate misissuance but may have caused delays in revocation status publication. The case has been resolved with the implementation of these changes.

Model: gpt-4o-mini Generated: 2026-06-13 21:31 UTC Confidence: 0.90
Chronology
  1. Set max-age directive to 24 hours in legacy OCSP software.
  2. Updated max-age directive to 6 hours.
  3. Reduced max-age directive to 4 hours and completed evaluation of OCSP responders.
Participants
Cade Cairns B Wilson
External References
Similar Local Cases
#1731164 RESOLVED Technical Compliance Opened 2021-09-16 · Closed 2023-02-22 · 60% similar
Google Trust Services: CRL validity period set to expected value plus one second
#1652581 RESOLVED Technical Compliance Opened 2020-07-13 · Closed 2023-02-22 · 49% similar
Google Trust Services: digitalSignature KeyUsage not set
#1873739 RESOLVED Technical Compliance Opened 2024-01-09 · Closed 2024-02-09 · 47% similar
Google Trust Services: uses "DNSSec-mostly" and DTPs for DNS resolution
#1735761 RESOLVED Technical Compliance Opened 2021-10-14 · Closed 2023-02-22 · 41% similar
Sectigo: CRL validity beyond CPS allowed value
#1772633 RESOLVED Technical Compliance Opened 2022-06-03 · Closed 2023-02-22 · 40% similar
IdenTrust: OCSP responses for subordinate CA exceed the validity period per CPS guidelines
#1793440 RESOLVED Technical Compliance Opened 2022-10-03 · Closed 2023-02-22 · 40% similar
D-TRUST: CRL not DER-encoded
#1914893 RESOLVED Technical Compliance Opened 2024-08-26 · Closed 2024-09-18 · 40% similar
Amazon Trust Services: CRL not DER-encoded
#1738191 RESOLVED Technical Compliance Opened 2021-10-28 · Closed 2023-02-22 · 39% similar
GDCA: CRL validity period exceeds allowed value by one second

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action