GoDaddy: Intermittent unauthorized OCSP response when certificate is freshly issued
GoDaddy reported an issue with their OCSP response mechanism, which intermittently returned 'unauthorized' responses for newly issued certificates. This problem arose due to latency in the OCSP response propagation process as GoDaddy scaled up its certificate issuance. The CA acknowledged the issue and committed to improvements, including adjusting the response syncing schedules and implementing a fast-track propagation script. A detailed report on the incident was promised once the short-term improvements were deployed. The issue has since been resolved, and the necessary actions have been completed.
- CPR sent to GoDaddy regarding unauthorized OCSP response
- Fast-track propagation script added to improve OCSP response times
- Community commenter — Noticed OCSP status is unavailable for freshly minted certificates on GoDaddy.
- GoDaddy — Provided preliminary response regarding latency in OCSP batching process.
- GoDaddy — Summarized the OCSP response sync mechanism degradation and actions taken.
- Mozilla representative — Indicated that all action items related to this incident have been completed.