← eMudhra Technologies Limited cases
Bugzilla #1917459 Validation Issue

eMudhra emSign PKI Services: OCSP responder time inconsistency for recently revoked certificates

RESOLVED FIXED eMudhra Technologies Limited
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case reports an OCSP responder time inconsistency affecting certificates revoked between 12:00 and 23:59 IST. An external researcher alerted emSign CA to a discrepancy in the OCSP response for a recently revoked certificate, where the OCSP and CRL timestamps differed by 12 hours. emSign CA investigated and determined the issue was caused by an incorrect IST-to-UTC time conversion configuration deployed to the OCSP responder, while the CRL timestamps were accurate. The investigation also found that, although OCSP responders updated at the correct frequency, the time conversion issue made the OCSP responses appear inconsistent at appropriate intervals. emSign CA developed a fix, tested it in staging, and deployed the corrected configuration to production, achieving full synchronization between OCSP and CRL; it also implemented enhanced monitoring and additional maker/checker controls. The bug was marked FIXED, and Mozilla indicated it would be closed on 14-Feb-2025 unless there were further issues or questions.

Model: gpt-5.4-nano Generated: 2026-06-13 21:25 UTC Revised: 2026-06-16 18:36 UTC Confidence: 0.86 7 comments
Chronology
  1. An external researcher alerted emSign CA to a discrepancy in OCSP responses for a recently revoked certificate.
  2. emSign CA identified an incorrect IST-to-UTC time conversion configuration in the OCSP responder and raised an incident after confirming the discrepancy.
  3. A corrected configuration was deployed to production and OCSP/CRL synchronization was achieved with enhanced monitoring and controls.
Thread Activity
  1. Emudhra representative — Filed an incident report describing the OCSP/CRL timestamp discrepancy, its IST-to-UTC configuration root cause, the limited impact, and the remediation steps including staging testing and production deployment.
  2. Hboeck representative — Provided attachments and stated he was the reporter, sharing OCSP/CRL evidence and the report sent to emSign.
  3. Emudhra representative — Requested that the Bugzilla be closed unless there were further questions.
  4. Mozilla representative — Replied with a reference to https://bugzilla.mozilla.org/show_bug.cgi?id=1924492#c2.
  5. Emudhra representative — Submitted a detailed incident description, root cause(s), remediation description, and commitments, stating all disclosed action items were completed and requesting closure.
  6. Mozilla representative — Stated Mozilla would close the bug on Friday, 14-Feb-2025, unless there were issues or questions.
Participants
Emudhra representative Hboeck representative Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2057520 UNCONFIRMED Ca Certificate Compliance Incident Self Reported Incident Validation Issue Opened 2026-07-24 Still Open · 75% similar
eMudhra emSign PKI Services: Invalid Subject Locality/State Values
#1666872 RESOLVED Validation Issue Opened 2020-09-23 · Closed 2023-02-22 · 68% similar
SSL.com: Insufficient validation evidence for the localityName attribute of an OV certificate
#1575880 RESOLVED Self Reported Incident Revocation Issue Validation Issue Opened 2019-08-22 · Closed 2023-02-22 · 66% similar
GlobalSign: SSL Certificates with US country code and invalid State/Prov
#1944815 RESOLVED Self Reported Incident Validation Issue Opened 2025-01-30 · Closed 2026-06-10 · 65% similar
GlobalSign: Organization-validated SMIME certificate with invalid organizationIdentifier for European country
#1637093 RESOLVED Validation Issue Opened 2020-05-11 · Closed 2023-02-22 · 65% similar
Multicert: AIA CA Issuer field pointing to PEM encoded cert
#1876593 RESOLVED Validation Issue Revocation Issue Opened 2024-01-25 · Closed 2024-06-06 · 65% similar
Google Trust Services: Failure to properly validate IP address
#1693304 RESOLVED Validation Issue Opened 2021-02-17 · Closed 2023-02-22 · 64% similar
FNMT: Issuance of QCP-n certificates without verifying identity
#1576789 RESOLVED Self Reported Incident Validation Issue Opened 2019-08-27 · Closed 2024-05-09 · 59% similar
Let's Encrypt: 2019.08.20 Incident: Incorrect OCSP responses under certain conditions

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action