← SSL.com cases
Bugzilla #1931636
Certificate Problem Report
SSL.com: Delay in publishing OCSP responses
RESOLVED
FIXED
SSL.com
AI Summary
SSL.com experienced a delay in publishing OCSP responses due to misconfigurations in two subCAs, which were not serving pre-signed OCSP responses as required. This issue was identified on November 13, 2024, and was promptly addressed by correcting the configuration. The incident was treated seriously, and a thorough investigation and root cause analysis were conducted. SSL.com has since implemented several improvements to their processes to prevent future occurrences.
Chronology
- SSL.com support received a report of OCSP response issues.
- Preliminary Incident Report posted.
- Final Incident Report submitted.
- All action items completed.
- Incident Report Closure Summary provided.
Participants
Rebecca Kelley
Ben Wilson
External References
Similar Local Cases
SSL.com: Entrust API and CAA checking
SSL.com: Issuance of certificates using keys previously reported as compromised
SSL.com: Failure to process CAA records from one SubCA
SSL.com: Expired certificate for a “Valid” Test Website
SSL.com: Revocation process requires submission to a form that is unusable
SSL.com: Insufficient serial number entropy
SSL.com: DCV bypass and issue fake certificates for any MX hostname
DigiCert: Late incident report for bug 1925106