Sectigo: Temporary failure to publish OCSP responses for newly issued certificates
Sectigo reported a self-discovered incident in its CertStatus system, which is used to sign and publish OCSP and CRLs. The incident was triggered by a database outage caused by the CertStatus primary database file system reaching 100% capacity, which prevented newly signed OCSP responses from being saved and published. Sectigo stated that the underlying cause was an unexpected change in the SSH Host Verification Key on the backup server used for offloading PostgreSQL WALs, which led to offloading breakdown and rapid disk growth. Sectigo reported that OCSP responses were not published in a timely manner for 6,957 certificates during the incident window. Sectigo also stated that issuance was not halted because the certificates were not considered misissued and the incident window was estimated to be short. In its remediation, Sectigo completed actions including adding disk capacity/partitions for temporary WAL storage, updating server configuration so WALs are saved separately from the database partition, reviewing and correcting OpenSSH daemon instances/configuration/host keys on the backup server, and setting up monitoring and alerting for WAL offloading failures. The bug is marked RESOLVED with resolution FIXED, and Sectigo requested closure after completing the action items.
- Sectigo’s CertStatus primary database reached 100% disk capacity, causing a database outage that prevented newly signed OCSP responses from being saved and published.
- Sectigo completed planned remediation action items related to the CertStatus incident.
- Sectigo posted a report closure summary stating remediation was completed and requested closure.
- Sectigo — Sectigo provided a preliminary incident report describing a CertStatus database outage and citing TLS BR 4.9.9 OCSP timeliness requirements.
- Sectigo — Sectigo posted a full incident report with the incident timeline, impact (6,957 certificates), and the stated root cause involving an SSH Host Verification Key change affecting WAL offloading.
- Sectigo — Sectigo reported completion of final remediation action items, including disk/partition changes, OpenSSH configuration/host key review, and monitoring/alerting for WAL offloading failures.
- Sectigo — Sectigo posted a report closure summary describing the incident, root cause, remediation, and requesting closure.
- CCADB representative — CCADB issued a final call for comments and noted the report would be closed unless questions were posted.