Certigna: Pre-certificates not recognised by the OCSP responder
The bug thread contains a preliminary incident report stating that the OCSP responder only recognises certificates issued by Certigna’s CAs. It further states that pre-certificates issued without a final leaf certificate are not recognised by the OCSP responder. The report cites TLS BR Version 2.2.7 section “4.9.9 On line revocation/status checking availability” as relevant policy. The thread explicitly says the source of the incident disclosure was a third party via a Certificate Problem Report. No resolution, remediation steps, or closure status are provided in the thread content shown. The bug is currently in ASSIGNED status.
- Certigna reported (via a preliminary incident report) that its OCSP responder does not recognise pre-certificates lacking final leaf certificates.
- j.allemandou@dhimyotis.com — Submitted a preliminary incident report describing OCSP recognition limitations for pre-certificates and noting the disclosure came from a third party via a Certificate Problem Report.