eMudhra emSign PKI Services : OCSP Responder Time Inconsistency
An inconsistency was identified in the OCSP responses for recently revoked certificates by eMudhra Technologies Limited. The issue stemmed from a configuration error that caused a 12-hour time difference between OCSP and CRL timestamps for certificates revoked between 12:00 and 23:59 IST. Although the OCSP responders were functioning correctly in terms of updates, the incorrect time conversion led to perceived discrepancies. The incident had minimal impact on customers, as revocation statuses were correctly displayed despite the timestamp issues. A fix was implemented, and enhanced configuration management practices were established to prevent future occurrences.
- External researcher reported OCSP response discrepancy.
- Investigation confirmed configuration error affecting time conversion.
- Corrected configuration deployed to production.
- Audit of configuration management process completed.
- Enhanced testing for OCSP/CRL behavior finalized.