← HARICA cases
Bugzilla #1878106 Certificate Problem Report

HARICA: Anomaly in OCSP services after CA software upgrade

RESOLVED FIXED HARICA
AI Summary

HARICA identified an issue with its OCSP services following a CA software upgrade, which resulted in newly issued certificates containing non-compliant OCSP responses. Specifically, the `nextUpdate` value for these responses exceeded the allowed duration, violating TLS BRs. The problem affected 161 TLS certificates, leading to connectivity issues for relying parties. HARICA quickly addressed the issue by fixing the code and purging the problematic responses, restoring proper OCSP functionality within hours. The incident prompted a thorough investigation and implementation of additional monitoring controls.

Model: gpt-4o-mini Generated: 2026-06-13 21:14 UTC Confidence: 1.00
Chronology
  1. Investigation initiated after reports of stale OCSP responses.
  2. Identified issue linked to CA software upgrade on January 16.
  3. Problematic OCSP responses purged and fix deployed.
  4. Incident report drafted and Bugzilla case opened.
  5. Case closed after all action items completed.
Participants
Dimitris Zacharopoulos Mathew Hodson Mozilla Team
Similar Local Cases
#1942130 RESOLVED Certificate Problem Report Opened 2025-01-16 · Closed 2025-05-01 · 59% similar
HARICA: S/MIME certificate issuance without proper validation
#1699796 RESOLVED Certificate Problem Report Opened 2021-03-19 · Closed 2023-02-22 · 59% similar
HARICA: Certificates with invalid policy tree
#1535509 RESOLVED Certificate Problem Report Opened 2019-03-15 · Closed 2023-02-22 · 58% similar
HARICA: Insufficient serial number entropy
#1535772 RESOLVED Certificate Problem Report Opened 2019-03-15 · Closed 2023-02-22 · 58% similar
HARICA: wrong characters in NC extension of Technically Constrained Intermediate CA Certificates
#1649945 RESOLVED Certificate Problem Report Opened 2020-07-02 · Closed 2023-02-22 · 58% similar
HARICA: Incorrect OCSP Delegated Responder Certificate
#1580393 RESOLVED Certificate Problem Report Opened 2019-09-11 · Closed 2022-11-14 · 57% similar
HARICA: OCSP Responder Returned "Unauthorized" for Some Precertificates
#1963629 RESOLVED Certificate Problem Report Opened 2025-04-30 · Closed 2025-07-08 · 56% similar
HARICA: One of the two Certificate Problem Report email aliases not working
#1824319 RESOLVED Certificate Problem Report Opened 2023-03-24 · Closed 2023-07-20 · 54% similar
Actalis: pre-certificates with “certificateHold” as the revocation reason

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action