CFCA OCSP responder certificate profile deviations and OCSP service issues
CFCA reported a compliance incident involving its OCSP infrastructure after a security researcher emailed the company about multiple non-conformance issues. The reported problems included OCSP responder certificate profile deviations, an OCSP service returning "unauthorized" for subordinate CA certificate status queries, and a separate CRL encoding issue that CFCA later split into another bug. CFCA stated that the issues were first received by email and were not initially processed through the official public CPR mechanism. CFCA later identified the OCSP-related issues as affecting three OCSP responder certificates and one subordinate CA certificate, and said the OCSP responder certificates were reissued with corrected profiles. The report was updated through action items, and CFCA stated that all action items were completed and requested closure.
- CFCA received a third-party report about OCSP responder certificate profile deviations and OCSP service issues.
- CFCA separated the CRL signatureAlgorithm issue into Bug 2033412.
- CFCA said the OCSP responder certificates had been reissued with correct BR 7.1.2.8 profiles.
- CFCA submitted a closure report stating that all action items were completed and requesting closure.
- Community commenter — CFCA opened a preliminary incident report describing third-party reported OCSP profile deviations and OCSP service issues.
- CCADB representative — Mozilla/CCADB asked that distinct and unrelated root causes be tracked in separate bugs.
- Community commenter — CFCA said it had split the CRL-related issues into Bug 2033412 and renamed this bug to focus on OCSP issues.
- Community commenter — CFCA reported that the OCSP responder certificates had been reissued and updated the action items table.
- Community commenter — CFCA posted a report closure summary stating the remediation was complete and requesting closure.
- CCADB representative — CCADB issued a final call for comments or questions before closure.