← IdenTrust Services, LLC cases
Bugzilla #1806728 Security Incident

IdenTrust: Bad OCSP Responses

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

IdenTrust reported an OCSP availability/response correctness issue discovered during a planned 24-hour test of OCSP traffic being diverted to AWS cloud infrastructure for scalability. During the test on December 15, 2022, IdenTrust received customer reports of timeout errors for TLS CRLs and later determined that a small number of certificates were mistakenly shown as "revoked" when checked via OCSP. IdenTrust’s investigation found problems replicating OCSP data to AWS: the replication missed status updates and incorrectly mapped target certificate status to "revoked" with an empty "revocationTime" field. The incorrect OCSP response was served 4,257 times over a 20-hour period, affecting 326 certificates, while 76,298,215 OCSP responses were served correctly. IdenTrust stopped the diversion of OCSP traffic and provided a full incident report describing the cause and timeline, then implemented corrective measures including changing the replication approach away from the "Continuous Query Notification" feature and updating testing to verify revocationTime and revocationReason matches. IdenTrust later confirmed that all implemented changes were working as expected and considered the issue fully resolved; Mozilla indicated it would close the bug on or about May 5, 2023. The bug is resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:18 UTC Revised: 2026-06-16 19:24 UTC Confidence: 0.90 7 comments
Chronology
  1. IdenTrust conducted a planned 24-hour OCSP traffic diversion test to AWS and received reports that some certificates appeared as revoked via OCSP.
  2. IdenTrust stopped the diversion of OCSP traffic after identifying a data issue.
  3. IdenTrust targeted implementation of corrective measures for the OCSP replication/status issue.
  4. IdenTrust confirmed implemented changes were working as expected and considered the issue fully resolved.
Thread Activity
  1. IdenTrust Services, LLC — IdenTrust stated it was investigating after receiving customer reports during a scheduled 24+ hour OCSP traffic diversion test and said a full incident report would follow by December 30, 2022.
  2. IdenTrust Services, LLC — IdenTrust provided a full incident report describing the OCSP replication problem, the number of affected certificates, and the timeline of actions taken.
  3. IdenTrust Services, LLC — IdenTrust confirmed it was on track to implement corrective measures by March 31, 2023 and planned an update by February 28, 2023.
  4. IdenTrust Services, LLC — IdenTrust reiterated it was on track for March 31, 2023 and listed corrective measures to change replication logic and improve testing.
  5. IdenTrust Services, LLC — IdenTrust reported a pre-production code change and said additional issues were found, expecting at least another month before production validation.
  6. IdenTrust Services, LLC — IdenTrust confirmed all implemented changes were working as expected and considered the issue fully resolved.
  7. Mozilla representative — Mozilla stated it would close the bug on or about May 5, 2023.
Participants
IdenTrust Services, LLC Mozilla representative
External References
Similar Local Cases
#1446121 RESOLVED Self Reported Incident Security Incident Opened 2018-03-15 · Closed 2023-02-22 · 69% similar
IdenTrust: Improper encoding of wildcard certificate
#1878106 RESOLVED Ca Security Vulnerability Security Incident Opened 2024-02-01 · Closed 2024-03-08 · 69% similar
HARICA: Anomaly in OCSP services after CA software upgrade
#1662346 RESOLVED Ca Security Vulnerability Security Incident Opened 2020-09-01 · Closed 2023-02-22 · 68% similar
DigiCert: OCSP responder returning invalid responses
#1816806 RESOLVED Ca Security Vulnerability Security Incident Opened 2023-02-15 · Closed 2023-03-09 · 68% similar
DigiCert: OCSP not responding issue
#1882904 RESOLVED Security Incident Opened 2024-02-29 · Closed 2025-02-12 · 68% similar
Google Trust Services: Incorrect OCSP responses for new ICAs under test
#1744795 RESOLVED Ca Security Vulnerability Security Incident Opened 2021-12-07 · Closed 2023-02-22 · 67% similar
DigiCert: Issuance of certs with weak keys (ROCA)
#1689589 RESOLVED Self Reported Incident Security Incident Opened 2021-01-29 · Closed 2023-02-22 · 67% similar
Telia: Disallowed curve (P-521) in leaf certificate
#1801345 RESOLVED Self Reported Incident Security Incident Opened 2022-11-18 · Closed 2023-07-21 · 67% similar
E-Tugra: Incident Report (Security Issues)

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action