← SSL.com cases
Bugzilla #1931636 Incident

SSL.com: Delay in publishing OCSP responses

RESOLVED FIXED SSL.com
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

On November 13, 2024, SSL.com reported a potential issue with OCSP responses for certificates issued from two subCAs, which were found to be misconfigured and not serving pre-signed OCSP responses. This incident was treated as a compliance failure, prompting SSL.com to initiate an internal investigation and the Certificate Problem Report (CPR) process. The misconfiguration was corrected the same day, and the issue was found to affect four subCAs from November 7 to November 13, 2024. SSL.com has since completed several remediation actions, including improvements to their post-ceremony processes and automated OCSP monitoring. A final incident report was submitted on February 7, 2025, confirming that all action items have been completed.

Model: gpt-4o-mini Generated: 2026-06-13 21:01 UTC Revised: 2026-06-16 18:50 UTC Confidence: 0.90 14 comments
Chronology
  1. SSL.com received a report of OCSP response issues affecting two subCAs.
  2. SSL.com posted a Preliminary Incident Report to Bugzilla.
  3. SSL.com submitted a final incident report confirming completion of all action items.
Thread Activity
  1. SSL.com — Posted a Preliminary Incident Report detailing the OCSP response issue.
  2. SSL.com — Submitted a Final Incident Report outlining the incident and remediation actions.
  3. SSL.com — Provided an Incident Report Closure Summary confirming all action items were completed.
Participants
SSL.com Mm representative Mozilla representative
External References
Similar Local Cases
#1932973 RESOLVED Certificate Misissuance Incident Opened 2024-11-22 · Closed 2025-04-07 · 100% similar
SSL.com: CAA Empty set handling results in Wildcard issuance
#1938236 RESOLVED Incident Revocation Issue Opened 2024-12-18 · Closed 2025-02-28 · 100% similar
SSL.com: Failure to process CAA records from one SubCA
#1927532 RESOLVED Incident Opened 2024-10-28 · Closed 2025-08-26 · 99% similar
SSL.com: Issuance of certificates using keys previously reported as compromised
#1722089 RESOLVED Incident Opened 2021-07-23 · Closed 2023-02-22 · 96% similar
SSL.com: Issuance of 3 EV TLS certificates without 2-person validation of the organization information
#1750631 RESOLVED Incident Revocation Issue Opened 2022-01-17 · Closed 2024-06-30 · 96% similar
SSL.com: Issuance of TLS certificates with domain validation methods prohibited by SC-45
#1579509 RESOLVED Incident Opened 2019-09-06 · Closed 2022-11-14 · 88% similar
SSL.com: Precertificates without corresponding certificates return OCSP value of "Unknown"
#1690807 RESOLVED Incident Self Reported Incident Opened 2021-02-04 · Closed 2023-02-22 · 71% similar
GlobalSign: RSA-1024 leaf certificate issued after 2013-12-31
#1905446 RESOLVED Incident Opened 2024-06-28 · Closed 2024-12-09 · 70% similar
IdenTrust: Unauthorized OCSP response on a Timestamp certificate

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action