← Microsoft Corporation cases
Bugzilla #1793443
Certificate Problem Report
Microsoft PKI Services: "unknown" OCSP response for issued certificates
RESOLVED
FIXED
Microsoft Corporation
AI Summary
Microsoft PKI Services encountered an issue where their OCSP responder returned an "unknown" status for several issued certificates. This problem was first identified on October 3, 2022, and was attributed to a failure in the OCSP publishing workflow. An exhaustive review revealed that 2221 certificates were affected, but none were issued to subscribers due to existing automation preventing issuance during failures. The issue was resolved by implementing new monitoring and manual processes to ensure future compliance with OCSP requirements.
Chronology
- Bug reported and initial investigation began.
- Preliminary incident report provided by Microsoft PKI Services.
- Clarification on OCSP publishing requirements discussed.
- Bug resolved.
Participants
Andrew Ayer
John Mason
Kathleen Wilson
External References
Similar Local Cases
Microsoft PKI Services: Malformed ICAs (Key Usage Malformed)
Microsoft PKI Services: Unrevoked 4 intermediate certificates
Microsoft PKI Services: Underscore in SAN
Microsoft PKI Services: OCSP Responder does not know a Certificate
Microsoft PKI Services: Null Character Bug and Microsoft Root CAs
Microsoft PKI Services: Malformed ICAs (missing certificate policy extensions)
Microsoft: improper disclosure of CRL
TWCA: "unknown" OCSP response for issued certificates