← Autoridad de Certificación (ANF AC) cases
Bugzilla #2050383 Ca Certificate Compliance Incident Self Reported Incident Revocation Issue Problem Reporting Failure

ANF AC incident report: OCSP inconsistency for a CT precertificate after interrupted issuance workflow

RESOLVED FIXED Autoridad de Certificación (ANF AC)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

ANF AC disclosed an incident involving a single CT precertificate that was published without a corresponding OCSP record, causing OCSP to return "does not know this certificate." The thread says the issue arose when SCT retrieval timed out, the issuance attempt was treated as failed, and a retry produced a new certificate with a different serial number. ANF AC registered the affected precertificate in OCSP on 2026-06-25, which resolved the immediate inconsistency. It then completed two corrective actions: changing the issuance workflow so the serial number is registered in OCSP before CT publication, and implementing independent end-to-end verification with alerts for missing or unexpected OCSP status. ANF AC also added automated OCSPWatch monitoring as an additional external validation layer, while stating that OCSPWatch is not its primary monitoring mechanism. On 2026-07-28, ANF AC filed a closure summary saying all action items were complete and requesting closure; CCADB then issued a final call for comments on 2026-07-29.

Model: gpt-5.4-mini Generated: 2026-06-26 17:46 UTC Revised: 2026-08-09 06:02 UTC Confidence: 0.96 11 comments
Chronology
  1. A precertificate was submitted to CT, SCT retrieval timed out, and a retry issued a new certificate with a different serial number.
  2. ANF AC registered the affected precertificate in the OCSP responder, resolving the inconsistency.
  3. ANF AC completed the issuance-workflow change so precertificates are registered in OCSP before CT publication.
  4. ANF AC completed the independent end-to-end verification action item.
  5. ANF AC filed a closure summary stating that all action items were completed and requested closure.
Thread Activity
  1. Autoridad de Certificación (ANF AC) — ANF AC posted a preliminary incident report describing the OCSP inconsistency and said it had registered the precertificate in OCSP.
  2. Autoridad de Certificación (ANF AC) — ANF AC posted the full incident report with the timeline, root cause, and statement that no additional orphaned precertificates were found.
  3. Autoridad de Certificación (ANF AC) — ANF AC said it had completed automated OCSPWatch monitoring as an additional alerting layer.
  4. Google representative — Google asked for details on OCSPWatch polling and what internal independent monitoring ANF AC uses beyond OCSPWatch.
  5. Mm representative — The commenter noted that the OCSPWatch API endpoint is undocumented/internal and that OCSPWatch is not a substitute for the CA's own monitoring.
  6. Autoridad de Certificación (ANF AC) — ANF AC explained its internal OCSP monitoring and described two corrective actions: workflow changes and end-to-end verification with alerts.
  7. Autoridad de Certificación (ANF AC) — ANF AC reported Action Item 1 complete and Action Item 2 in final validation.
  8. Autoridad de Certificación (ANF AC) — ANF AC reported Action Item 2 complete and said all action items were completed.
  9. CCADB representative — CCADB said the report had gone stale and asked ANF AC to file a Closure Report if ready.
  10. Autoridad de Certificación (ANF AC) — ANF AC filed a closure summary describing the incident, root cause, remediation, and request for closure.
  11. CCADB representative — CCADB issued a final call for comments or questions and said the report would be closed if no further input arrived.
Participants
Autoridad de Certificación (ANF AC) Google representative Mm representative CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1974325 RESOLVED Incident Self Reported Incident Opened 2025-06-26 · Closed 2025-07-16 · 100% similar
ANF AC: Test Certificates Non-Compliance
#1973236 RESOLVED Incident Policy Document Issue Self Reported Incident Opened 2025-06-20 · Closed 2025-07-09 · 94% similar
ANF AC: Delayed Disclosure of Updated Policy Documents in CCADB
#1969296 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-05-29 · Closed 2025-07-22 · 87% similar
GoDaddy: Certificates with invalid embedded SCT signatures
#2009491 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Repository Issue Opened 2026-01-09 · Closed 2026-02-17 · 86% similar
DigiCert: Several non-functioning AIA URLs
#1962809 RESOLVED Self Reported Incident Revocation Issue Opened 2025-04-25 · Closed 2025-07-28 · 86% similar
SSL.com: Expired certificate for a “Valid” Test Website
#1963456 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-04-29 · Closed 2025-07-25 · 86% similar
GoDaddy: CA Certificates with HTTPS URL in AIA Field
#1950574 RESOLVED Ca Certificate Compliance Incident Revocation Issue Opened 2025-02-26 · Closed 2025-09-15 · 86% similar
SECOM: S/MIME CA Modified Opinion Report of Cybertrust Japan (CTJ)
#1970565 RESOLVED Audit Finding Self Reported Incident Opened 2025-06-05 · Closed 2025-07-08 · 86% similar
ANF AC: Finding #2 ETSI Audit - Information security policy not updated on the website

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action