← DigiCert cases
Bugzilla #1816806 Ca Security Vulnerability Security Incident

DigiCert: OCSP responder not updating issue (auditor-discovered)

RESOLVED FIXED DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

DigiCert reported that during an audit of its production systems in Europe, auditors (BDO) found that the OCSP responder was not updating as expected, with the last update on 13 January 2023. DigiCert stated that the issue affected OCSP responses only and that there were no impacted certificates. DigiCert said the problem was caused by a failure of an API: after DigiCert updated to 64-bit, the configured API key kept failing the permission check, and the failed API was used to transfer OCSP responses from origin servers to the European system. DigiCert deployed related web server changes in Europe on 13 January 2023, then on 9 February 2023 the auditor notified DigiCert Compliance, DigiCert reviewed and investigated, confirmed and escalated to Engineering, and resolved and tested the issue. DigiCert restored service by generating and installing a new API key, and it added monitoring/alerts for the European OCSP responder plus additional alert-auditing steps and checklist requirements for future releases. The bug was requested to be closed after no further updates were needed, and Mozilla indicated it would close it on or about 8 March 2023; the bug resolution is FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 11:41 UTC Revised: 2026-06-16 19:09 UTC Confidence: 0.86 5 comments
Chronology
  1. DigiCert production team deployed web server changes related to OCSP operation in its European data centre.
  2. DigiCert confirmed and resolved the OCSP responder update issue after auditor notification and engineering escalation.
  3. DigiCert added monitoring to the new European systems for the OCSP responder.
Thread Activity
  1. DigiCert — Reported that BDO auditors found the OCSP responder was not updating (last update 13-Jan-2023), described the API/64-bit permission-check failure cause, and outlined remediation steps including a new API key and added monitoring/alert coverage.
  2. DigiCert — Asked if there were any questions and requested closing the bug if none.
  3. Community commenter — Agreed that Ben could close the bug since there were no questions.
  4. Community commenter — Asked Ben if anything else was needed from DigiCert.
  5. Mozilla representative — Indicated Mozilla would close the bug on or about Wed, 8-March-2023.
Participants
DigiCert Community commenter Mozilla representative
External References
Similar Local Cases
#1662346 RESOLVED Ca Security Vulnerability Security Incident Opened 2020-09-01 · Closed 2023-02-22 · 100% similar
DigiCert: OCSP responder returning invalid responses
#1744795 RESOLVED Ca Security Vulnerability Security Incident Opened 2021-12-07 · Closed 2023-02-22 · 99% similar
DigiCert: Issuance of certs with weak keys (ROCA)
#1675684 RESOLVED Ca Security Vulnerability Security Incident Opened 2020-11-06 · Closed 2023-02-22 · 98% similar
DigiCert: Private Keys Disclosed by Customers as Part of CSR
#1820269 RESOLVED Ca Security Vulnerability Security Incident Opened 2023-03-03 · Closed 2024-06-30 · 91% similar
DigiCert: 4 CRLs unavailable or not responding
#1577014 RESOLVED Security Incident Opened 2019-08-27 · Closed 2023-02-22 · 89% similar
DigiCert: OCSP services returns 1 byte
#1878106 RESOLVED Ca Security Vulnerability Security Incident Opened 2024-02-01 · Closed 2024-03-08 · 79% similar
HARICA: Anomaly in OCSP services after CA software upgrade
#1424305 RESOLVED Ca Security Vulnerability Incident Opened 2017-12-08 · Closed 2023-02-22 · 78% similar
DigiCert: Microsoft: Incident report for Microsoft Dynamics incident
#1838315 RESOLVED Ca Security Vulnerability Incident Opened 2023-06-13 · Closed 2023-10-12 · 69% similar
IdenTrust: Certificate with missing details flagged by OCSP Watch

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action