IdenTrust: Certificate with missing details flagged by OCSP Watch
IdenTrust reported that, during routine monitoring on June 7, 2023, it detected an IdenTrust-issued certificate flagged by the SSLMATE OCSP Watch monitoring tool as requiring attention. Id enTrust stated the issue was corrected the same day, and that investigation found the flagging was caused by a system outage that resulted in issuance of a precertificate without a serial number, leading to an unknown OCSP status. Id enTrust cited the Subscriber (Server) Certificate Profile in B.R. Section 7.1.2.7, stating that inclusion of a serial number is mandatory. The CA said it would prevent recurrence by enhancing its code with a stronger locking mechanism to avoid multiple retries during certificate retrieval that could lead to incomplete certificates, with an implementation target of September 30, 2023 and monthly progress updates. Id enTrust later reported that the code revision was tested and deployed on 9/30/2023 and was working as expected, and it considered the issue closed as completed. Mozilla indicated it would close the bug on 11-Oct-2023 unless questions remained, and the bug is resolved as FIXED.
- IdenTrust detected an OCSP Watch flag for an IdenTrust-issued certificate and corrected the discrepancy the same day.
- IdenTrust deployed a code change intended to prevent recurrence of incomplete certificate issuance during retrieval retries.
- IdenTrust confirmed the deployed code was working as expected and marked the issue closed.
- IdenTrust Services, LLC — IdenTrust said it noticed an IdenTrust-issued certificate in the SSLMATE OCSP watch monitor tool on June 7, 2023, that the issue was corrected the same day, and that it would supply a complete incident report by June 24, 2023.
- IdenTrust Services, LLC — IdenTrust provided details: routine monitoring detected the issue on June 7, it was due to a system outage causing a precertificate without a serial number, and it described a timeline and planned remediation via stronger locking to avoid multiple retrieval retries.
- IdenTrust Services, LLC — IdenTrust reported it was on track to deploy the fix and would provide a status update by August 31, 2023.
- IdenTrust Services, LLC — IdenTrust reported it remained on track to deploy the fix by the end of September and would provide a status update by September 30, 2023.
- Internet Security Research Group — Let’s Encrypt’s pp orada asked whether IdenTrust could attach the precertificate generated without the serial number.
- IdenTrust Services, LLC — IdenTrust explained that a hardware malfunction led to resource limitations and performance issues, multiple retrieval attempts generated a precertificate whose serial number was overwritten, and it published the precertificate to CT (crt.sh link provided).
- IdenTrust Services, LLC — IdenTrust stated the code revision was tested and on track for the September 30 release date, with a final update planned for October 2.
- IdenTrust Services, LLC — IdenTrust confirmed the code was successfully deployed on 9/30/2023 and was working as expected, and it considered the issue closed as completed.
- Mozilla representative — Mozilla stated it would close the bug on 11-Oct-2023 unless there were questions or concerns still to address.