← SSL.com cases
Bugzilla #1957140 Repository Issue

SSL.com: "unknown" OCSP response for issued certificates

RESOLVED FIXED SSL.com
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

SSL.com reported an incident where OCSP responders for 67 certificates returned an "unknown" status, violating their Certificate Practice Statement (CPS) regarding online revocation checking. The issue was identified following a third-party Certificate Problem Report submitted on March 25, 2025. SSL.com took immediate action to resolve the OCSP response issue and began an investigation into the root cause, which was linked to intermittent failures in inserting newly issued certificates into their CA database. A full incident report was provided, detailing the timeline and remediation actions. The incident was resolved by implementing controls to automatically detect and import missing certificates, and SSL.com committed to improving their monitoring systems. The case is now closed as of July 31, 2025.

Model: gpt-4o-mini Generated: 2026-06-13 21:01 UTC Revised: 2026-06-16 18:52 UTC Confidence: 0.90 20 comments
Chronology
  1. Third-party Certificate Problem Report submitted regarding OCSP errors.
  2. Incident Closure Summary posted, detailing resolution and future commitments.
Thread Activity
  1. SSL.com — Preliminary Incident Report posted, summarizing the OCSP issue and immediate actions taken.
  2. SSL.com — Full Incident Report provided, detailing the root cause and timeline of the incident.
  3. SSL.com — Report Closure Summary posted, confirming the completion of all action items.
Participants
SSL.com Community commenter CCADB representative
External References
Similar Local Cases
#1942270 RESOLVED Revocation Issue Repository Issue Opened 2025-01-17 · Closed 2025-04-07 · 82% similar
SSL.com: Revocation process requires submission to a form that is unusable
#1962809 RESOLVED Self Reported Incident Revocation Issue Opened 2025-04-25 · Closed 2025-07-28 · 75% similar
SSL.com: Expired certificate for a “Valid” Test Website
#1927532 RESOLVED Incident Opened 2024-10-28 · Closed 2025-08-26 · 70% similar
SSL.com: Issuance of certificates using keys previously reported as compromised
#1932973 RESOLVED Certificate Misissuance Incident Opened 2024-11-22 · Closed 2025-04-07 · 70% similar
SSL.com: CAA Empty set handling results in Wildcard issuance
#1961406 RESOLVED Certificate Misissuance Opened 2025-04-18 · Closed 2025-07-02 · 70% similar
SSL.com: DCV bypass and issue fake certificates for any MX hostname
#2009543 RESOLVED Ca Certificate Compliance Incident Repository Issue Opened 2026-01-10 · Closed 2026-02-09 · 67% similar
Microsoft PKI Services: Improper Disclosure of CRLs – Does Not Match CA Subject
#1999241 RESOLVED Incident Repository Issue Opened 2025-11-10 · Closed 2025-12-24 · 67% similar
eMudhra emSign PKI Services : Delayed Publication of Issuing CA Certificates in CCADB
#2007297 RESOLVED Incident Repository Issue Opened 2025-12-21 · Closed 2026-02-23 · 67% similar
eMudhra emSign PKI Services: CRL URL Mismatch Between CCADB Disclosure and Issued Certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action