← Google Trust Services LLC cases
Bugzilla #1773556
Certificate Problem Report
Google Trust Services: Incorrect OCSP responses for certain certificates
RESOLVED
FIXED
Google Trust Services LLC
AI Summary
Google Trust Services LLC identified an issue where their OCSP responders were returning HTTP 404 responses for a small number of domains issued under GTS CA 1D4. The problem was detected on June 9, 2022, and a fix was deployed shortly thereafter, significantly reducing the error rate. The incident did not result in certificate misissuance, but it highlighted a misconfiguration during a migration to a new OCSP responder software version. Google Trust Services has since implemented more sensitive monitoring and is working to deprecate the older responder.
Chronology
- Issue detected; OCSP responders returning HTTP 404
- Fix deployed, error rate reduced
- Migration from older responder completed
Participants
Cade Cairns
External References
Similar Local Cases
Google Trust Services: Incorrect OCSP response for issued certificate
Google Trust Services: Failure to respond to CPR within 24 hours
Google Trust Services: invalid CRL reason code
Google Trust Services: Failure to provide preliminary report within 24h
Google Trust Services: OCSP serving issue 2020-04-09
Google Trust Services: SXG certificates issued without correctly checking CAA restrictions
Google Trust Services: Missing authorization audit log entry for certificate issuance
Google Trust Services: Incorrect OCSP responses for new ICAs under test