← Certainly LLC cases
Bugzilla #1798053
Certificate Problem Report
Certainly: Serving Bad OCSP Responses
RESOLVED
FIXED
Certainly LLC
AI Summary
Certainly LLC experienced an incident where their OCSP service returned 'unauthorized' responses for valid certificates. The issue was identified on October 24, 2022, during testing of a new monitoring tool. A series of fixes were implemented, restoring correct OCSP responses for approximately 50,000 certificates by October 25. The root cause was a change in serial number prefixes that was not properly configured, leading to unauthorized responses. Remediation steps have been completed, and monitoring continues to ensure no recurrence.
Chronology
- Incident declared after unauthorized OCSP responses detected.
- Correct OCSP responses restored for all certificates.
- Remediation of the incident completed.
Participants
Wayne Thayer
bwilson@mozilla.com
External References
Similar Local Cases
Certainly: Serving Expired OCSP Responses
Certainly: Serving invalid or incomplete CRLs
Certainly: Early CRL Entry Removal
Certainly: TLS Using ALPN TLS Version and OID
Let's Encrypt: OCSP "unauthorized" responses
Certainly: Sample Websites Unavailable
GlobalSign: OCSP responders found to respond signed by the default CA when passed an invalid issuer in request
Let's Encrypt: Early CRL Removal Incident