← IdenTrust Services, LLC cases
Bugzilla #1905446
Certificate Problem Report
IdenTrust: Unauthorized OCSP response on a Timestamp certificate
RESOLVED
FIXED
IdenTrust Services, LLC
AI Summary
On June 27, 2024, IdenTrust discovered an unauthorized OCSP response error for a timestamping certificate, violating their CPS Section 9.6.1. The certificate was missing from the OCSP database, which was promptly corrected after identification. A full incident report was provided, detailing the root cause as a procedural oversight during the certificate's creation. IdenTrust has since integrated this certificate type into their OCSP validation process to prevent future occurrences.
Chronology
- Unauthorized OCSP response error discovered
- Certificate added to OCSP database
- Integration of certificate type into OCSP validation process completed
Participants
roots@identrust.com
aaron@letsencrypt.org
bwilson@mozilla.com
External References
Similar Local Cases
IdenTrust: TLS Certificates with outdated certificate profile
IdenTrust: EV TLS certificate with invalid Jurisdiction state for government entity
IdenTrust: Expired CRL served
IdenTrust: S/MIME certificates with Invalid document Identification Scheme
IdenTrust: Unavailable CRL and OCSP Responders
IdenTrust: Undisclosed Unrevoked ICAs
TWCA: Revocation delay for TLS certificates with non-critical basicConstraints
SSL.com: Delayed revocation of certificate with weak key