eMudhra emSign PKI Services: OCSP responder returned unauthorized for publicly logged precertificates; incident report closed after remediation
This case concerns emSign CA’s OCSP handling for publicly logged precertificates from incomplete issuance transactions. The CA reported that its responder returned RFC 6960 “unauthorized” responses beyond the 15-minute availability requirement in BR §4.9.9 because OCSP status provisioning was tied to final certificate issuance and a separate workflow for failed issuance transactions did not reliably complete in time. After an external report, emSign filed a preliminary incident report, then a full incident report, and later a closure summary. The CA said it deployed a systemic fix on June 23, 2026 to provision OCSP status at the precertificate logging stage, updated and published its CP/CPS, and provisioned OCSP status for all affected precertificates identified in its review. In its closure summary, emSign said a complete review of records from January 15, 2025 through June 23, 2026 found 81 precertificates that had not received OCSP status within 15 minutes, while 7 later precertificates from failed issuance transactions were within the requirement. The bug is now resolved and the incident report was placed into final call for comments, with CCADB stating it would close the report on or about 2026-07-30 if no further issues were raised.
- BR §4.9.9 15-minute OCSP availability requirement period began for the review window later examined by emSign.
- A publicly logged precertificate was recorded and final certificate issuance did not complete, leaving OCSP status unprovisioned within the required window.
- Additional publicly logged precertificates were recorded from failed issuance transactions and OCSP status was not provisioned within 15 minutes.
- emSign deployed a systemic fix to provision OCSP status at the precertificate logging stage.
- emSign submitted a report closure summary stating all action items were complete and closure was requested.
- CCADB issued a final call for comments or questions before closure.
- Emudhra representative — Filed a preliminary incident report describing RFC 6960 “unauthorized” OCSP responses for three publicly logged precertificates and attributing the issue to a separate workflow for failed issuance transactions.
- Emudhra representative — Filed a full incident report stating the behavior was not compliant with BR §4.9.9 and that the CA had concluded an authoritative OCSP response was required within 15 minutes of precertificate logging.
- Emudhra representative — Reported action items to provision OCSP status at precertificate logging stage, update the internal workflow, and update the CP/CPS.
- Community commenter — As the external reporter, criticized the timing and handling of the incident report and asked about the CA’s process for recognizing and disclosing the issue.
- Emudhra representative — Acknowledged the compliance issue should have been identified earlier and said CPRs relating to OCSP, revocation, CT logging, or certificate status would be routed to compliance-qualified reviewers immediately.
- Emudhra representative — Reported the results of a complete review, including 81 precertificates outside the 15-minute requirement and 7 later precertificates that were within the requirement, and said the CP/CPS update was completed.
- Emudhra representative — Submitted a report closure summary stating all action items were complete, the systemic fix was deployed, and closure was requested.
- CCADB representative — Posted a final call for comments or questions and said the incident report would be closed on or about 2026-07-30 if no further issues were raised.