← IdenTrust Services, LLC cases
Bugzilla #1806728
Certificate Problem Report
IdenTrust: Bad OCSP Responses
RESOLVED
FIXED
IdenTrust Services, LLC
AI Summary
IdenTrust experienced issues with OCSP responses during a scheduled test on December 15, 2022, where a small number of certificates incorrectly displayed as revoked due to data replication problems. A total of 326 certificates were affected, leading to incorrect responses being served over a 20-hour period. The incident did not involve the issuance of TLS certificates. IdenTrust has since implemented corrective measures to prevent future occurrences, and the issue was resolved by April 28, 2023.
Chronology
- Diverting OCSP traffic from on-premise to AWS began.
- Reports received from customers experiencing connectivity issues.
- Corrective measures implemented.
- All changes confirmed working as expected.
Participants
IdenTrust
Mozilla
External References
Similar Local Cases
IdenTrust: Unavailable CRL for IdenTrust ‘DST Root CA X3’.
IdenTrust: Failure to provide OCSP responses for valid ICA certificates
IdenTrust: Missing Revocation Reasons in CRL
IdenTrust: Certificate with missing details flagged by OCSP Watch
IdenTrust: Expired CRLs
IdenTrust: Expired ICAs CRLs
IdenTrust: Pre-certificates without a final certificate showing OCSP error
IdenTrust: Service Degradation