← IdenTrust Services, LLC cases
Bugzilla #1905446 Incident

IdenTrust: Unauthorized OCSP response on a Timestamp certificate

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

IdenTrust reported a compliance issue discovered through its daily monitoring of SSLMate’s OCSP watch. On June 27, 2024, one of its issued timestamping certificates was flagged with an “unauthorized” OCSP response error, which the CA stated violated CPS Section 9.6.1 regarding maintaining an online 24x7 publicly accessible repository with current certificate status. IdenTrust’s initial investigation found the leaf timestamping certificate was missing from the OCSP database, and it was immediately added; OCSP checks then succeeded and the SSLMate alert cleared. In its full incident report, IdenTrust attributed the problem to omitting an important step during the certificate ceremony: the certificate was not added for OCSP verification into the database. The CA stated it would incorporate a validation step to ensure successful OCSP validation for this certificate type, due by 2024-10-24. IdenTrust later reported that it integrated the timestamping certificate type into its existing OCSP validation process and confirmed the issue was fully resolved. The bug was resolved as FIXED, with IdenTrust indicating there were no outstanding remediation items and Mozilla asking to close the issue.

Model: gpt-5.4-nano Generated: 2026-06-13 21:28 UTC Revised: 2026-06-16 19:27 UTC Confidence: 0.90 10 comments
Chronology
  1. IdenTrust’s timestamping certificate was flagged by SSLMate OCSP watch with an “unauthorized” OCSP response error.
  2. IdenTrust added the missing timestamping certificate to the OCSP database and OCSP checks began succeeding.
  3. IdenTrust integrated the timestamping certificate type into its OCSP validation process and confirmed full resolution.
Thread Activity
  1. IdenTrust Services, LLC — IdenTrust reported that its daily OCSP monitoring found an “unauthorized” OCSP response error for a CA-issued timestamping certificate and said it was missing from the OCSP database; it was added and the issue corrected while root-cause investigation continued.
  2. IdenTrust Services, LLC — IdenTrust provided a full incident report describing the impact (OCSP checks returning an error), the timeline, and a root cause of omitting the step to add the certificate for OCSP verification into the database; it listed an action item to add this certificate type to OCSP validation checking.
  3. Internet Security Research Group — Aaron Gable asked whether IdenTrust planned actions to prevent future instances, such as automating timestamping certificate creation so it cannot be created without being added to the OCSP database.
  4. IdenTrust Services, LLC — IdenTrust replied that the timestamping certificate uses a unique HSM-based creation process and said it would prevent recurrence by incorporating a validation step to ensure successful OCSP validation.
  5. IdenTrust Services, LLC — IdenTrust stated it was on track to complete the action item by 2024-10-24 and scheduled the next update for August 31, 2024.
  6. IdenTrust Services, LLC — IdenTrust reiterated it was on track to complete the action item by 2024-10-24 and would provide another update by 2024-09-30.
  7. IdenTrust Services, LLC — IdenTrust again stated it was on track to complete the action item by 2024-10-24.
  8. IdenTrust Services, LLC — IdenTrust reported it successfully integrated the timestamping certificate type into its existing OCSP validation process and confirmed the issue was fully resolved.
  9. IdenTrust Services, LLC — IdenTrust said there were no outstanding remediation items and requested closing the issue if there were no further community questions.
  10. Mozilla representative — Mozilla indicated it would look at closing the issue on Wed 6-Nov-2024 unless there were issues to discuss.
Participants
IdenTrust Services, LLC Internet Security Research Group Mozilla representative
Similar Local Cases
#1838315 RESOLVED Ca Security Vulnerability Incident Opened 2023-06-13 · Closed 2023-10-12 · 98% similar
IdenTrust: Certificate with missing details flagged by OCSP Watch
#1900492 RESOLVED Incident Opened 2024-06-03 · Closed 2026-06-10 · 97% similar
IdenTrust: Invalid OrganizationIdentifier in S/MIME certificates
#1753287 RESOLVED Incident Opened 2022-02-02 · Closed 2024-07-08 · 97% similar
IdenTrust: Validation Source for EV Certificates not Publicly Disclosed
#1709192 RESOLVED Incident Opened 2021-05-03 · Closed 2023-02-22 · 96% similar
IdenTrust: Unavailable CRL for IdenTrust ‘DST Root CA X3’.
#2025913 RESOLVED Self Reported Incident Incident Opened 2026-03-24 · Closed 2026-05-18 · 89% similar
IdenTrust: Full Incident Report for Bug 2014609 was not published within 14 days of discovering the issue
#2014590 RESOLVED Self Reported Incident Incident Opened 2026-02-04 · Closed 2026-04-23 · 88% similar
IdenTrust: Unauthorized OCSP responses for cross-signed roots
#2025596 RESOLVED Self Reported Incident Incident Opened 2026-03-23 · Closed 2026-05-18 · 88% similar
IdenTrust: Delay in updating a Bugzilla ticket Bug 2014610 - Next update
#1542082 RESOLVED Incident Self Reported Incident Opened 2019-04-04 · Closed 2023-02-22 · 88% similar
IdenTrust: Failure to disclose Unconstrained intermediate Within 7 Days

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action