DigiCert: inconsistent revocation / OCSP / CRL behavior
The bug was filed by an external reporter who had reported multiple certificates with compromised private keys to DigiCert, referencing a Fortigate private key leak. The reporter observed that one certificate was already expired and therefore did not need revocation, but they noted unusual revocation-related behavior for OCSP and CRL responses. They reported three perceived issues: an expired certificate still returning an OCSP response of "good", only one of two certificates sharing the same key being revoked, and an inconsistency where OCSP reported a certificate as revoked while the CRL did not. After re-checking, the reporter clarified that one of the certificates they thought was a separate new certificate was actually the final certificate for the originally reported precertificate, and that both were expired, which they said made one of the issues ignorable; they also suggested the CRL/OCSP timing might be acceptable. DigiCert responded that these were not policy violations and that the behavior was expected given how OCSP works, and asked that the bug be closed as invalid. Mozilla indicated it would close the bug on 24-Jan-2025 unless there were further concerns, and DigiCert thanked Mozilla.
- External reporter submitted observations about OCSP/CRL behavior for certificates related to compromised private keys reported to DigiCert.
- DigiCert stated the observed behavior was expected and requested the bug be closed as invalid.
- Mozilla scheduled closure of the bug on 24-Jan-2025 absent further concerns.
- DigiCert acknowledged the outcome.
- Hboeck representative — Reported perceived OCSP/CRL inconsistencies for certificates tied to compromised private keys and attached current OCSP/CRL replies.
- Hboeck representative — Clarified that one earlier “new” certificate was actually the final certificate for the precertificate and that both were expired, reducing the severity of the earlier issues.
- DigiCert — Agreed the observations were not policy violations, said the behavior is expected for OCSP, and requested closing the bug as invalid.
- Mozilla representative — Stated the bug would be closed on Friday, 24-Jan-2025, unless there were additional questions or concerns.
- DigiCert — Thanked Mozilla.