← D-TRUST cases
Bugzilla #1879529 Revocation Issue

D-Trust: OCSP validation service returned "unknown" instead of "good" for 3 OV certificates

RESOLVED FIXED D-TRUST
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

D-Trust reported an incident in which its OCSP validation service responded "unknown" instead of "good" for three OV certificates. The affected certificates were issued on January 26, 2024, and the OCSP responses were incorrect for a period of 14 days. D-Trust stated that isolated irregularities in its CA software with reduced availability and individual failures led to an interaction problem between the CA software and the component responsible for publishing certificate status, so the three certificates were produced but not published to the OCSP system. D-Trust also reported that a CA system update preceded the issue and that a patch from the CA system manufacturer was provided and being tested. D-Trust said its monitoring system recorded the error, but the escalation chain did not work for this specific case, so no manual or automated intervention occurred. As remediation, D-Trust added monitoring rules to ensure escalation for this error case and reported that these rules were in place starting 19.02. at 9:00AM. The bug was marked RESOLVED with resolution FIXED, and Mozilla indicated the case was completed and scheduled for closure on 5-Apr-2024.

Model: gpt-5.4-nano Generated: 2026-06-13 21:27 UTC Revised: 2026-06-16 18:44 UTC Confidence: 0.90 4 comments
Chronology
  1. D-Trust issued three OV certificates that later experienced incorrect OCSP responses.
  2. Mozilla received an email report from Ben Wilson about the OCSP "unknown" responses.
  3. D-Trust reported that the OCSP validation service began responding "good" for the affected OV certificates.
  4. D-Trust reported monitoring rules were extended to ensure escalation for this error case.
  5. Mozilla scheduled the case for closure after completion.
Thread Activity
  1. Bdr representative — Opened a preliminary incident report stating that for three OV certificates D-Trust’s OCSP validation service was responding "unknown" instead of "good" and that investigation was underway.
  2. Bdr representative — Submitted an incident report describing the impact (14 days) and root cause, and listed action items including manual OCSP watch checks and extending monitoring rules for escalation.
  3. Bdr representative — Provided a quick update that, since 19.02. at 9:00AM, the monitoring rules to ensure escalation were in place.
  4. Mozilla representative — Noted the case appeared completed and would be scheduled for closure on Friday, 5-Apr-2024.
Participants
Bdr representative Mozilla representative
Similar Local Cases
#2029013 ASSIGNED Revocation Issue Opened 2026-04-02 Still Open · 95% similar
D-Trust: Missing Pre-Signing Linting for TLS Issuance
#1924385 RESOLVED Ca Certificate Compliance Revocation Issue Closure Request Opened 2024-10-13 · Closed 2025-07-16 · 94% similar
D-Trust: Missed Revocation of TLS certificates affected by Bugzilla 1884714
#2037000 ASSIGNED Self Reported Incident Certificate Misissuance Problem Reporting Failure Opened 2026-05-05 Still Open · 79% similar
D-Trust: Missing Pre-Sign Linting for S/MIME Issuing CAs
#1753123 RESOLVED Revocation Issue Self Reported Incident Opened 2022-02-01 · Closed 2023-01-04 · 69% similar
Let's Encrypt: Failure to provide OCSP Responses for some certificates
#1763203 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Revocation Issue Opened 2022-04-05 · Closed 2023-02-22 · 69% similar
Sectigo: Incorrect OCSP responses
#1900129 RESOLVED Revocation Issue Opened 2024-05-31 · Closed 2024-06-28 · 69% similar
Certainly: Serving invalid or incomplete CRLs
#1790693 RESOLVED Self Reported Incident Revocation Issue Opened 2022-09-13 · Closed 2023-03-24 · 68% similar
SSL.com: Issuance of 1 EV TLS certificate using a Registration/Incorporation Agency not included in our approved public list.
#1718785 RESOLVED Self Reported Incident Revocation Issue Opened 2021-06-30 · Closed 2024-06-30 · 68% similar
Sectigo: 2020 failure to respond to CPRs discovered

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action