← D-TRUST cases
Bugzilla #1879529
Certificate Problem Report
D-Trust: "unknown" OCSP response for issued certificates
RESOLVED
FIXED
D-TRUST
AI Summary
D-Trust experienced an issue where its OCSP validation service returned 'unknown' instead of 'good' for three OV certificates issued on January 26, 2024. This problem persisted for 14 days, leading to potential trust issues for the affected certificates. The root cause was identified as isolated irregularities in the CA software following a system update, which affected the interaction with the OCSP system. D-Trust has since implemented monitoring improvements to prevent similar issues in the future.
Chronology
- Updating the affected CA system
- Certificates issued
- Issue reported by Ben Wilson
- Internal analysis started
- End of analysis
- Scheduled closure of the case
Participants
Enrico Entschew
Ben Wilson
External References
Similar Local Cases
D-Trust: Missing Pre-Signing Linting for TLS Issuance
D-Trust: QCStatement with http link of PKI Disclosure Statements
D-Trust: TLS Precertificates Exceeding the Maximum Validity Period Allowed by the TLS Baseline Requirements
D-Trust: Notice to affected Subscriber and person filing CPR not sent within 24 hours
D-Trust: Missed Revocation of TLS certificates affected by Bugzilla 1884714
D-Trust: Issuance of an EV certificate containing a mixup of the Subject's postalCode and localityName
D-TRUST: syntax error in one tls certificate
D-TRUST: Precertificate OU > 64 Characters