← HARICA cases
Bugzilla #1878106 Ca Security Vulnerability Security Incident

HARICA: Anomaly in OCSP services after CA software upgrade

RESOLVED FIXED HARICA
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

HARICA reported that after a CA software upgrade it detected an anomaly in its OCSP services that resulted in new issued TLS certificates having pre-signed OCSP responses with a non-compliant `nextUpdate` value. HARICA said it was alerted by a subscriber that wrong OCSP responses were being served, and investigation found that the issue began after the upgrade and could affect 161 TLS certificates. HARICA stated that the problematic OCSP responses had `nextUpdate` more than 10 days from `thisUpdate`, violating TLS BRs section 4.9.10, and that the OCSP response refresh service did not update them in time (missing the four-day mark). HARICA reported that it fixed the problematic code the same day, purged the problematic OCSP responses from its front-end certificate status servers, and that affected subscribers were able to get proper OCSP responses within 1 hour after the production fix. HARICA also shared action items, including requesting a root cause analysis from the CA software vendor, updating testing instructions, and implementing additional OCSP monitoring controls and OCSP/CRL linters, and later stated that all action items were completed. Mozilla indicated the bug could be closed after completion of the action items, and the bug is resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:14 UTC Revised: 2026-06-16 19:16 UTC Confidence: 0.90 8 comments
Chronology
  1. HARICA’s CA software upgrade triggered an OCSP compliance issue affecting issuance of TLS certificates’ pre-signed OCSP responses.
  2. HARICA identified and remediated the OCSP anomaly, purging problematic OCSP responses and deploying a fix to resume issuing services.
  3. HARICA opened the Bugzilla incident report after drafting the incident report and coordinating with the software vendor.
  4. HARICA reported that all listed action items were completed.
  5. Mozilla closed the case after confirming completion of action items; resolution recorded as FIXED.
Thread Activity
  1. HARICA — Opened the incident report describing the OCSP anomaly after a CA software upgrade, the non-compliant `nextUpdate` issue, the affected certificate count, and the same-day fix and purging of problematic OCSP responses.
  2. Community commenter — Asked what CA software HARICA was using to help other CAs investigate potential similar impact.
  3. HARICA — Responded that HARICA uses EJBCA Enterprise and that the issue is triggered in version 8.2.0; noted Keyfactor would inform customers and prepare a public announcement.
  4. HARICA — Posted a link to Keyfactor’s announcement about the OCSP compliance issue in EJBCA version 8.2.0.
  5. HARICA — Provided an update to action items with due dates, including requesting vendor root cause analysis and implementing OCSP monitoring controls and OCSP/CRL linters.
  6. HARICA — Updated the action items table, marking additional items as completed and adjusting completion dates.
  7. HARICA — Reported that all action items were completed and described testing notes about running an OCSP linter in batch mode.
  8. Mozilla representative — Stated that since all action items were completed, the matter could be closed and indicated intent to close on 8-March-2024.
Participants
HARICA Community commenter Mozilla representative
Similar Local Cases
#1662346 RESOLVED Ca Security Vulnerability Security Incident Opened 2020-09-01 · Closed 2023-02-22 · 79% similar
DigiCert: OCSP responder returning invalid responses
#1816806 RESOLVED Ca Security Vulnerability Security Incident Opened 2023-02-15 · Closed 2023-03-09 · 79% similar
DigiCert: OCSP not responding issue
#1744795 RESOLVED Ca Security Vulnerability Security Incident Opened 2021-12-07 · Closed 2023-02-22 · 78% similar
DigiCert: Issuance of certs with weak keys (ROCA)
#1675684 RESOLVED Ca Security Vulnerability Security Incident Opened 2020-11-06 · Closed 2023-02-22 · 77% similar
DigiCert: Private Keys Disclosed by Customers as Part of CSR
#1879602 RESOLVED Security Incident Self Reported Incident Opened 2024-02-09 · Closed 2024-07-19 · 76% similar
Entrust: OCSP response signed with SHA-1
#1838315 RESOLVED Ca Security Vulnerability Incident Opened 2023-06-13 · Closed 2023-10-12 · 70% similar
IdenTrust: Certificate with missing details flagged by OCSP Watch
#1820269 RESOLVED Ca Security Vulnerability Security Incident Opened 2023-03-03 · Closed 2024-06-30 · 69% similar
DigiCert: 4 CRLs unavailable or not responding
#1806728 RESOLVED Security Incident Opened 2022-12-20 · Closed 2023-05-05 · 69% similar
IdenTrust: Bad OCSP Responses

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action