← Google Trust Services LLC cases
Bugzilla #1882904 Security Incident

Google Trust Services: Incorrect OCSP responses for new ICAs under test

RESOLVED FIXED Google Trust Services LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Google Trust Services (GTS) identified an issue with incorrect OCSP responses for new intermediate CAs during testing. The problem was traced to the legacy OCSP responder architecture, which had complexities due to its dual infrastructure. GTS issued an incident report detailing the background, impact, and timeline of the issue, noting that 3,301 OCSP requests received unauthorized responses while 7,922 certificates were issued during the problem period. GTS has since completed a remediation plan to ensure the legacy OCSP pipeline is agnostic to ICA changes and has implemented additional monitoring and validation steps. The incident is now resolved.

Model: gpt-4o-mini Generated: 2026-06-13 21:35 UTC Revised: 2026-06-16 18:49 UTC Confidence: 0.85 13 comments
Chronology
  1. GTS investigates OCSP status information issues for new intermediate CAs.
  2. GTS publishes an incident report detailing the OCSP response issues.
  3. GTS completes remediation actions related to the OCSP incident.
Thread Activity
  1. Google representative — GTS is investigating an issue with OCSP status information not being correctly updated on new intermediate CAs.
  2. Google representative — GTS provides an incident report summarizing the OCSP response issues.
  3. Google representative — GTS announces the completion of the remediation actions related to the OCSP incident.
Participants
Google representative Community commenter Mozilla representative
External References
Similar Local Cases
#1879602 RESOLVED Security Incident Self Reported Incident Opened 2024-02-09 · Closed 2024-07-19 · 77% similar
Entrust: OCSP response signed with SHA-1
#1806728 RESOLVED Security Incident Opened 2022-12-20 · Closed 2023-05-05 · 68% similar
IdenTrust: Bad OCSP Responses
#1662346 RESOLVED Ca Security Vulnerability Security Incident Opened 2020-09-01 · Closed 2023-02-22 · 67% similar
DigiCert: OCSP responder returning invalid responses
#1816806 RESOLVED Ca Security Vulnerability Security Incident Opened 2023-02-15 · Closed 2023-03-09 · 67% similar
DigiCert: OCSP not responding issue
#1878106 RESOLVED Ca Security Vulnerability Security Incident Opened 2024-02-01 · Closed 2024-03-08 · 67% similar
HARICA: Anomaly in OCSP services after CA software upgrade
#1801345 RESOLVED Self Reported Incident Security Incident Opened 2022-11-18 · Closed 2023-07-21 · 67% similar
E-Tugra: Incident Report (Security Issues)
#1744795 RESOLVED Ca Security Vulnerability Security Incident Opened 2021-12-07 · Closed 2023-02-22 · 66% similar
DigiCert: Issuance of certs with weak keys (ROCA)
#1689589 RESOLVED Self Reported Incident Security Incident Opened 2021-01-29 · Closed 2023-02-22 · 66% similar
Telia: Disallowed curve (P-521) in leaf certificate

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action