← Google Trust Services LLC cases
Bugzilla #1882904
Certificate Problem Report
Google Trust Services: Incorrect OCSP responses for new ICAs under test
RESOLVED
FIXED
Google Trust Services LLC
AI Summary
Google Trust Services (GTS) encountered issues with OCSP responses for newly issued intermediate CAs, resulting in incorrect 'unauthorized' responses for 3,301 OCSP requests. The incident was attributed to the complexity of maintaining both legacy and newer OCSP responder architectures. GTS has since implemented action items to improve the configuration and monitoring of OCSP responders, with all action items completed by April 26, 2024. The company plans to continue supporting both OCSP systems until deprecation is feasible, pending updates from root programs.
Chronology
- GTS reports investigation into OCSP issues.
- Incident report detailing OCSP response issues is published.
- GTS completes all action items related to the incident.
Participants
Google Trust Services
Mozilla
External References
Similar Local Cases
Google Trust Services: Failure to properly validate IP address
Google Trust Services: Self-audit tooling MPIC perspective verification inconsistency
Google Trust Services: Short OCSP outage
Google Trust Services: Missing authorization audit log entry for certificate issuance
Google Trust Services: Outdated BR version in some validation records
Google Trust Services: Failure to revoke subscriber certificates within BR timeframe
Google Trust Services: Incorrect OCSP responses for certain certificates
Google Trust Services: OCSP serving issue 2020-04-09