Certigna: Pre-certificates not recognised by the OCSP responder
The bug thread documents an incident where Certigna’s OCSP responder does not recognise pre-certificates that were issued but for which no final leaf certificate was generated. The disclosure source is stated as a third party via a Certificate Problem Report. Certigna reported a non-compliance period from 2024-05-13 to 2026-06-19, with no impact identified on certificates and totals of 0 TLS certificates and 5 precertificates. Certigna stated that it revoked two still-valid pre-certificates and updated the CRL and OCSP responder on 2026-06-17. Certigna also updated its TLS certificate issuance process and technical procedures on 2026-06-18 to revoke pre-certificates when the final DNS CAA check fails, and raised staff awareness of the workflow changes on 2026-06-19. On 2026-07-01, Certigna submitted a report closure summary stating all action items were completed, and CCADB issued a final call for comments before closure. The bug is currently marked RESOLVED with resolution FIXED.
- A pre-certificate was issued where the final DNS CAA check was invalid, preventing generation of the associated final certificate.
- Certigna received third-party notification (via a Certificate Problem Report) that its OCSP responder did not recognise two certificates.
- Certigna revoked two still-valid pre-certificates and updated the CRL and OCSP responder.
- Certigna updated its TLS certificate issuance process and technical procedures to revoke pre-certificates when the final DNS CAA check fails.
- Certigna raised staff awareness of the updated procedures and workflow.
- Certigna submitted a closure summary requesting closure after stating all action items were completed.
- Dhimyotis representative — Posted a preliminary incident report stating that pre-certificates without a final leaf certificate are not recognised by Certigna’s OCSP responder and that disclosure came from a third party via a Certificate Problem Report.
- Dhimyotis representative — Posted the full incident report with timeline, stated no impact, counts (0 TLS certificates, 5 precertificates), revocation of two still-valid pre-certificates, and process/procedure updates.
- Dhimyotis representative — Submitted a report closure summary describing the root cause and remediation and requesting closure after stating all action items were completed.
- CCADB representative — Issued a final call for comments/questions, stating the incident report would be closed on approximately 2026-07-08 if no further input was received.