← Certainly LLC cases
Bugzilla #1798053 Incident

Certainly: Serving Bad OCSP Responses

RESOLVED FIXED Certainly LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

On 24 October 2022, Certainly became aware that its OCSP service was returning an “unauthorized” response for some valid certificates. The issue was discovered while testing a new monitoring tool, when a Certainly engineer observed OCSP query errors for certificates on www.certainly.com. Certainly investigated and declared an incident, applied fixes to an active data center, identified a bug in the OCSP monitor, and applied additional fixes to an inactive data center; it also deployed a fix for the monitoring bug and updated its testing checklist. The problem was not related to the certificates themselves; it affected OCSP responses for approximately 50,000 certificates issued between 18 September and 17 October 2022. Certainly attributed the cause to a change in leaf certificate serial number prefixes where the OCSP responder required both old and new prefixes to remain configured, and it also found that an external check bug prevented an alert from firing in this scenario. The thread states that remediation was completed, correct OCSP responses were restored for all certificates on 25 October 2022 at 21:05 UTC, and Certainly continued monitoring the bug for questions until it was closed.

Model: gpt-5.4-nano Generated: 2026-06-13 21:27 UTC Revised: 2026-06-16 18:17 UTC Confidence: 0.90 6 comments
Chronology
  1. Certainly’s OCSP service began returning “unauthorized” responses for some valid certificates, triggering an incident response.
  2. Correct OCSP responses were restored for all affected certificates.
  3. Remediation was reported complete and no further questions were received; community closure was planned.
Thread Activity
  1. Fastly representative — Wayne Thayer reported that Certainly discovered the OCSP “unauthorized” responses during monitoring-tool testing, provided a detailed incident timeline, described the approximate scope (~50,000 certificates), and explained the serial-prefix configuration and monitoring-check issues.
  2. Fastly representative — Wayne Thayer stated that remediation was completed and that Certainly would continue monitoring the bug for comments.
  3. Fastly representative — Wayne Thayer said monitoring would continue for questions or feedback.
  4. Fastly representative — Wayne Thayer reported remediation was complete, no questions had been received, and monitoring would continue until closure.
  5. Mozilla representative — Ben Wilson asked whether the community had additional questions or issues and said he planned to close the bug around 23-Nov-2022.
  6. Fastly representative — Wayne Thayer said Certainly representatives continued to monitor the bug for questions or feedback.
Participants
Fastly representative Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1771238 RESOLVED Incident Opened 2022-05-25 · Closed 2023-02-22 · 99% similar
Certainly: Serving Expired OCSP Responses
#1968836 RESOLVED Incident Self Reported Incident Opened 2025-05-28 · Closed 2025-08-26 · 78% similar
Certainly: Sample Websites Unavailable
#2052399 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Repository Issue Opened 2026-07-03 Still Open · 71% similar
Certainly: Expired certificates on "Valid" and "Revoked" test websites
#2052085 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Audit Finding Opened 2026-07-02 Still Open · 70% similar
Certainly: Missing audit log entries for certificates issued during capacity testing
#1750631 RESOLVED Incident Revocation Issue Opened 2022-01-17 · Closed 2024-06-30 · 68% similar
SSL.com: Issuance of TLS certificates with domain validation methods prohibited by SC-45
#1843173 RESOLVED Incident Problem Reporting Failure Opened 2023-07-12 · Closed 2023-09-29 · 68% similar
NETLOCK: CRL Error on CRL Watch of NETLOCK DVCA CRL
#1602999 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Opened 2019-12-11 · Closed 2024-05-09 · 68% similar
Microsoft PKI Services: Loss of Archived Firewall logs from Retention Store
#1573490 RESOLVED Incident Opened 2019-08-13 · Closed 2023-02-22 · 68% similar
PKIoverheid: CIBG insufficient serial number entropy

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action