← Microsec Ltd. cases
Bugzilla #1844514 Revocation Issue Incident

MICROSEC: Incident report - No OCSP status response for 2 Precertificates

RESOLVED FIXED Microsec Ltd.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Microsec reported an incident where its OCSP responder failed to send correct OCSP status responses for two precertificates. Microsec said it first became aware of the problem via a phone notification and then opened an internal JIRA ticket to investigate. Microsec’s investigation concluded that a configuration problem in its CA program prevented the precertificate from being added to the OCSP responders database when at least one CT log server could respond with an SCT, and that improper error management flow caused the issuance process to terminate without issuing the TLS certificate. As immediate remediation, Microsec added the two missing precertificates to its OCSP responders database and revoked the two problematic precertificates. Microsec also implemented a fix and improved its certificate issuance process so that the precertificate is added to an internal certificate status repository dedicated to OCSP responders immediately after creation, before it is sent to CT log servers, and set up automated checking of https://sslmate.com/labs/ocsp_watch/. In later status updates, Microsec reported no further OCSP problems on the site and stated that the incident would be listed in its next AAL in 2023Q4; Mozilla indicated it anticipated closing the bug on 29-Sep-2023. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:13 UTC Revised: 2026-06-16 19:15 UTC Confidence: 0.90 9 comments
Chronology
  1. Microsec received a phone notification about OCSP problems affecting two precertificates.
  2. Microsec completed a deep investigation and implemented a fix to improve the certificate issuance process and OCSP handling.
  3. Microsec reported no further OCSP problems on sslmate.com/labs/ocsp_watch/ during the one-week live test.
  4. Microsec reported automated testing was running properly and it planned no further action regarding the incident.
  5. Mozilla indicated it anticipated closing the bug on 29-Sep-2023.
Thread Activity
  1. Microsec representative — Microsec reported that its OCSP responder failed to send correct answers for two precertificates and provided an incident report including a timeline and remediation steps.
  2. Microsec representative — Microsec provided a status report describing daily checks of https://sslmate.com/labs/ocsp_watch/, installation of an improved CA program, and planned completion of automated testing subscription work.
  3. Microsec representative — Microsec reported continued manual checks, no further OCSP problems, and ongoing issues with the automated testing tool subscription.
  4. Daknob representative — Mozilla asked clarification about whether the issue was configuration vs. code, how errors are handled in the issuance pipeline, and whether underlying error-handling compliance was reviewed.
  5. Microsec representative — Microsec explained the issuance error handling and described the updated process for adding precertificates to its internal status store and handling CT log registration outcomes.
  6. Microsec representative — Microsec reported no further OCSP problems and continued efforts to resolve automated testing subscription issues.
  7. Microsec representative — Microsec reported activating another automated testing tool, no further OCSP problems, and that the incident was discussed with its auditor and would be listed in its next AAL in 2023Q4.
  8. Mozilla representative — Mozilla thanked Microsec for the update and stated it anticipated closing the bug on Friday, 29-Sep-2023.
Participants
Microsec representative Daknob representative Mozilla representative
Similar Local Cases
#1889699 RESOLVED Certificate Misissuance Incident Revocation Issue Opened 2024-04-04 · Closed 2024-08-28 · 88% similar
Microsec: Disallowed subject attribute field in DV certificate
#1391055 RESOLVED Ca Certificate Compliance Incident Opened 2017-08-16 · Closed 2023-02-22 · 87% similar
Microsec: Non-BR-Compliant Certificate Issuance
#1750631 RESOLVED Incident Revocation Issue Opened 2022-01-17 · Closed 2024-06-30 · 77% similar
SSL.com: Issuance of TLS certificates with domain validation methods prohibited by SC-45
#1728384 RESOLVED Certificate Misissuance Incident Opened 2021-08-31 · Closed 2023-02-22 · 77% similar
Microsec: Misissuance of one OV certificate with Key Usage KeyEncipherment
#1763203 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Revocation Issue Opened 2022-04-05 · Closed 2023-02-22 · 76% similar
Sectigo: Incorrect OCSP responses
#1676352 RESOLVED Certificate Misissuance Incident Opened 2020-11-10 · Closed 2023-02-22 · 76% similar
Microsec: Certificate validity period greater than 398 days
#1950574 RESOLVED Ca Certificate Compliance Incident Revocation Issue Opened 2025-02-26 · Closed 2025-09-15 · 76% similar
SECOM: S/MIME CA Modified Opinion Report of Cybertrust Japan (CTJ)
#1938236 RESOLVED Incident Revocation Issue Opened 2024-12-18 · Closed 2025-02-28 · 74% similar
SSL.com: Failure to process CAA records from one SubCA

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action