← Sectigo cases
Bugzilla #1946927
Certificate Problem Report
Sectigo: Intermittent OCSP unauthorized responses for certificates older than 15 minutes
RESOLVED
FIXED
Sectigo
AI Summary
Sectigo experienced intermittent OCSP unauthorized responses for certificates issued more than 15 minutes prior, violating TLS Baseline Requirements. The issue was traced to replication delays in six out of eighteen database replicas, leading to inconsistent OCSP responses. Sectigo has since implemented several corrective measures, including replacing faulty network devices and enhancing their monitoring and documentation processes. The incident has been resolved, and all action items have been completed.
Chronology
- Bug reported regarding OCSP unauthorized responses.
- Initial incident report issued by Sectigo.
- Report closure summary provided by Sectigo.
Participants
Matt Nordhoff
Martijn Katerbarg
External References
Similar Local Cases
Sectigo: Temporary failure to publish OCSP responses for newly issued certificates
Sectigo: Partial OCSP response publication delay for newly issued certificates
Sectigo: Incorrect OCSP responses
Sectigo: Incomplete Subject organizationName
Sectigo: HTML encoded characters in subject attribute values
Sectigo: Lack of documentation for vulnerability NVD rating adjustment
Sectigo: OV reuse data applied for wrong organization
Sectigo: OCSP and CRL traffic not being proxied for 3 Subordinate CAs