Google Trust Services: Short OCSP outage
Google Trust Services (GTS) reported that its OCSP responders experienced an outage for approximately two hours, during which certificate status requests returned HTTP 503 errors. GTS stated the outage was caused by an access control configuration error during a migration to consolidate and improve access control group management, which unintentionally denied data read permissions needed by the OCSP responder service. GTS said no certificates were impacted and that issuance was not stopped because the outage affected only retrieval of status information, not certificate validity. GTS identified the root cause as a lack of staged rollouts for legacy groups used by the OCSP service, along with incomplete dependency visibility and over-reliance on automated safety checks. GTS resolved the incident by rolling back the configuration change and re-enabling the necessary access control groups so OCSP responders resumed serving valid status information. In the thread, GTS also reported completing remediation actions including enabling “production-critical” protections for OCSP-related access groups, auditing production workloads for similar access control configurations, and implementing a policy to verify critical access control changes in test/staging before applying to production. The bug was resolved as FIXED, with GTS requesting closure after stating all action items were completed.
- GTS OCSP responders returned HTTP 503 errors for about two hours due to an access control configuration error during an access control migration.
- GTS published a public full incident report attachment for the Bugzilla case.
- GTS reported incident closure summary and stated remediation actions were completed.
- Mozilla CA Program bug status reached RESOLVED with resolution FIXED.
- Google representative — GTS submitted a preliminary incident report stating the OCSP outage lasted about two hours, was caused by an access control issue, and that it would publish a full incident report by 2026-04-30 while requesting nextUpdate be set to then.
- Google representative — GTS added a public incident report attachment for the bug.
- Google representative — GTS corrected the bug by stating it mistakenly re-added the needInfo flag and that the flag should be removed.
- Google representative — GTS provided an action-item table and stated the remaining action items were completed, requesting nextUpdate be set to 2026-05-22.
- Google representative — GTS posted a report closure summary describing the incident, root causes, remediation, and commitment that all action items were completed, requesting closure.
- CCADB representative — CCADB posted a final call for comments/questions and stated the bug would be closed around 2026-05-29.