HARICA: Anomaly in OCSP services after CA software upgrade
HARICA reported that after a CA software upgrade it detected an anomaly in its OCSP services that resulted in new issued TLS certificates having pre-signed OCSP responses with a non-compliant `nextUpdate` value. HARICA said it was alerted by a subscriber that wrong OCSP responses were being served, and investigation found that the issue began after the upgrade and could affect 161 TLS certificates. HARICA stated that the problematic OCSP responses had `nextUpdate` more than 10 days from `thisUpdate`, violating TLS BRs section 4.9.10, and that the OCSP response refresh service did not update them in time (missing the four-day mark). HARICA reported that it fixed the problematic code the same day, purged the problematic OCSP responses from its front-end certificate status servers, and that affected subscribers were able to get proper OCSP responses within 1 hour after the production fix. HARICA also shared action items, including requesting a root cause analysis from the CA software vendor, updating testing instructions, and implementing additional OCSP monitoring controls and OCSP/CRL linters, and later stated that all action items were completed. Mozilla indicated the bug could be closed after completion of the action items, and the bug is resolved as FIXED.
- HARICA’s CA software upgrade triggered an OCSP compliance issue affecting issuance of TLS certificates’ pre-signed OCSP responses.
- HARICA identified and remediated the OCSP anomaly, purging problematic OCSP responses and deploying a fix to resume issuing services.
- HARICA opened the Bugzilla incident report after drafting the incident report and coordinating with the software vendor.
- HARICA reported that all listed action items were completed.
- Mozilla closed the case after confirming completion of action items; resolution recorded as FIXED.
- HARICA — Opened the incident report describing the OCSP anomaly after a CA software upgrade, the non-compliant `nextUpdate` issue, the affected certificate count, and the same-day fix and purging of problematic OCSP responses.
- Community commenter — Asked what CA software HARICA was using to help other CAs investigate potential similar impact.
- HARICA — Responded that HARICA uses EJBCA Enterprise and that the issue is triggered in version 8.2.0; noted Keyfactor would inform customers and prepare a public announcement.
- HARICA — Posted a link to Keyfactor’s announcement about the OCSP compliance issue in EJBCA version 8.2.0.
- HARICA — Provided an update to action items with due dates, including requesting vendor root cause analysis and implementing OCSP monitoring controls and OCSP/CRL linters.
- HARICA — Updated the action items table, marking additional items as completed and adjusting completion dates.
- HARICA — Reported that all action items were completed and described testing notes about running an OCSP linter in batch mode.
- Mozilla representative — Stated that since all action items were completed, the matter could be closed and indicated intent to close on 8-March-2024.