MICROSEC: Incident report - No OCSP status response for 2 Precertificates
Microsec reported an incident where its OCSP responder failed to send correct OCSP status responses for two precertificates. Microsec said it first became aware of the problem via a phone notification and then opened an internal JIRA ticket to investigate. Microsec’s investigation concluded that a configuration problem in its CA program prevented the precertificate from being added to the OCSP responders database when at least one CT log server could respond with an SCT, and that improper error management flow caused the issuance process to terminate without issuing the TLS certificate. As immediate remediation, Microsec added the two missing precertificates to its OCSP responders database and revoked the two problematic precertificates. Microsec also implemented a fix and improved its certificate issuance process so that the precertificate is added to an internal certificate status repository dedicated to OCSP responders immediately after creation, before it is sent to CT log servers, and set up automated checking of https://sslmate.com/labs/ocsp_watch/. In later status updates, Microsec reported no further OCSP problems on the site and stated that the incident would be listed in its next AAL in 2023Q4; Mozilla indicated it anticipated closing the bug on 29-Sep-2023. The bug is marked RESOLVED with resolution FIXED.
- Microsec received a phone notification about OCSP problems affecting two precertificates.
- Microsec completed a deep investigation and implemented a fix to improve the certificate issuance process and OCSP handling.
- Microsec reported no further OCSP problems on sslmate.com/labs/ocsp_watch/ during the one-week live test.
- Microsec reported automated testing was running properly and it planned no further action regarding the incident.
- Mozilla indicated it anticipated closing the bug on 29-Sep-2023.
- Microsec representative — Microsec reported that its OCSP responder failed to send correct answers for two precertificates and provided an incident report including a timeline and remediation steps.
- Microsec representative — Microsec provided a status report describing daily checks of https://sslmate.com/labs/ocsp_watch/, installation of an improved CA program, and planned completion of automated testing subscription work.
- Microsec representative — Microsec reported continued manual checks, no further OCSP problems, and ongoing issues with the automated testing tool subscription.
- Daknob representative — Mozilla asked clarification about whether the issue was configuration vs. code, how errors are handled in the issuance pipeline, and whether underlying error-handling compliance was reviewed.
- Microsec representative — Microsec explained the issuance error handling and described the updated process for adding precertificates to its internal status store and handling CT log registration outcomes.
- Microsec representative — Microsec reported no further OCSP problems and continued efforts to resolve automated testing subscription issues.
- Microsec representative — Microsec reported activating another automated testing tool, no further OCSP problems, and that the incident was discussed with its auditor and would be listed in its next AAL in 2023Q4.
- Mozilla representative — Mozilla thanked Microsec for the update and stated it anticipated closing the bug on Friday, 29-Sep-2023.