IdenTrust: Unauthorized OCSP responses for cross-signed roots
IdenTrust Services, LLC self-disclosed an incident involving unauthorized OCSP responses for four cross-signed certificates. The issue was identified during routine monitoring, revealing that the corresponding Intermediate Certificate Authorities (ICAs) were not included in the OCSP configuration prior to the certificates' disclosure to the Common CA Database (CCADB). A full incident report was submitted, detailing the timeline of events and root causes, including configuration gaps and process oversights. The CA has completed all action items to remediate the issue and has requested closure of the incident report.
- Non-compliance start date identified
- Non-compliance identified
- Preliminary incident disclosed
- Full incident report submitted
- Incident report closure requested
- IdenTrust Services, LLC — Preliminary incident report submitted detailing unauthorized OCSP responses.
- Community commenter — Questioned the self-disclosure claim due to reliance on a third-party tool.
- IdenTrust Services, LLC — Full incident report provided with detailed analysis and action items.
- IdenTrust Services, LLC — Requested closure of the incident report.
- CCADB representative — Final call for comments before closure of the incident report.