IdenTrust: Unauthorized OCSP response on a Timestamp certificate
IdenTrust reported a compliance issue discovered through its daily monitoring of SSLMate’s OCSP watch. On June 27, 2024, one of its issued timestamping certificates was flagged with an “unauthorized” OCSP response error, which the CA stated violated CPS Section 9.6.1 regarding maintaining an online 24x7 publicly accessible repository with current certificate status. IdenTrust’s initial investigation found the leaf timestamping certificate was missing from the OCSP database, and it was immediately added; OCSP checks then succeeded and the SSLMate alert cleared. In its full incident report, IdenTrust attributed the problem to omitting an important step during the certificate ceremony: the certificate was not added for OCSP verification into the database. The CA stated it would incorporate a validation step to ensure successful OCSP validation for this certificate type, due by 2024-10-24. IdenTrust later reported that it integrated the timestamping certificate type into its existing OCSP validation process and confirmed the issue was fully resolved. The bug was resolved as FIXED, with IdenTrust indicating there were no outstanding remediation items and Mozilla asking to close the issue.
- IdenTrust’s timestamping certificate was flagged by SSLMate OCSP watch with an “unauthorized” OCSP response error.
- IdenTrust added the missing timestamping certificate to the OCSP database and OCSP checks began succeeding.
- IdenTrust integrated the timestamping certificate type into its OCSP validation process and confirmed full resolution.
- IdenTrust Services, LLC — IdenTrust reported that its daily OCSP monitoring found an “unauthorized” OCSP response error for a CA-issued timestamping certificate and said it was missing from the OCSP database; it was added and the issue corrected while root-cause investigation continued.
- IdenTrust Services, LLC — IdenTrust provided a full incident report describing the impact (OCSP checks returning an error), the timeline, and a root cause of omitting the step to add the certificate for OCSP verification into the database; it listed an action item to add this certificate type to OCSP validation checking.
- Internet Security Research Group — Aaron Gable asked whether IdenTrust planned actions to prevent future instances, such as automating timestamping certificate creation so it cannot be created without being added to the OCSP database.
- IdenTrust Services, LLC — IdenTrust replied that the timestamping certificate uses a unique HSM-based creation process and said it would prevent recurrence by incorporating a validation step to ensure successful OCSP validation.
- IdenTrust Services, LLC — IdenTrust stated it was on track to complete the action item by 2024-10-24 and scheduled the next update for August 31, 2024.
- IdenTrust Services, LLC — IdenTrust reiterated it was on track to complete the action item by 2024-10-24 and would provide another update by 2024-09-30.
- IdenTrust Services, LLC — IdenTrust again stated it was on track to complete the action item by 2024-10-24.
- IdenTrust Services, LLC — IdenTrust reported it successfully integrated the timestamping certificate type into its existing OCSP validation process and confirmed the issue was fully resolved.
- IdenTrust Services, LLC — IdenTrust said there were no outstanding remediation items and requested closing the issue if there were no further community questions.
- Mozilla representative — Mozilla indicated it would look at closing the issue on Wed 6-Nov-2024 unless there were issues to discuss.