← Autoridad de Certificación (ANF AC) cases
Bugzilla #2050383 Incident Problem Reporting Failure Ccadb Disclosure Issue

ANF AC: Incident Report - OCSP "unknown" response for CT precertificate

ASSIGNED Autoridad de Certificación (ANF AC)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

ANF AC reported an operational incident involving a Certificate Transparency (CT) precertificate whose OCSP status was observed as "does not know this certificate". ANF AC stated that the precertificate had been submitted to CT, but during the SCT retrieval workflow the issuance process timed out; when the request was retried, a new certificate was issued with a different serial number, leaving the original precertificate published in CT without a corresponding OCSP record. ANF AC said it registered the affected precertificate in its OCSP responder on 2026-06-25, resolving the OCSP inconsistency, and that a review of historical issuance records found no additional orphaned precertificates. ANF AC also described that the incident was brought to its attention via a third-party notification referencing OCSPWatch, which was initially misclassified as spam and not seen by operations until a second contact was added to the thread. In response to the incident, ANF AC reported completing an action item to implement automated monitoring of OCSPWatch by polling the OCSPWatch API and alerting operations when issues affecting ANF AC are detected. The Google root program participant asked for details on ANF AC’s OCSPWatch polling and requested information about independent internal monitoring and controls beyond OCSPWatch.

Model: gpt-5.4-nano Generated: 2026-06-26 17:46 UTC Confidence: 0.55 5 comments
Chronology
  1. ANF AC generated and submitted a CT precertificate, then the SCT retrieval workflow timed out and a retry issued a new certificate with a different serial number.
  2. ANF AC received a third-party notification referencing OCSPWatch but it was incorrectly classified as spam.
  3. ANF AC identified the incident after a second ANF AC contact was added to the notification thread.
  4. ANF AC registered the affected precertificate in the OCSP responder, resolving the OCSP inconsistency.
  5. ANF AC reported completing automated OCSPWatch monitoring integration and discussed remediation details in the thread.
Thread Activity
  1. yulier.nunez@anf.es — ANF AC provided a preliminary incident report describing the OCSP inconsistency for a CT precertificate and said it registered the precertificate in OCSP on 2026-06-25.
  2. yulier.nunez@anf.es — ANF AC posted a full incident report with a timeline, root cause description (SCT retrieval timeout leading to a new serial on retry), and impact details (1 precertificate, 0 remaining valid certificates).
  3. yulier.nunez@anf.es — ANF AC stated it completed an action item to implement automated OCSPWatch monitoring by polling the OCSPWatch API and alerting operations.
  4. chrome-root-program@google.com — Google asked ANF AC to clarify OCSPWatch polling details and to describe independent internal monitoring/alerting and controls beyond OCSPWatch.
  5. agwa-bugs@mm.beanwood.com — The commenter noted that the referenced OCSPWatch API endpoint is undocumented/internal and that OCSPWatch is not a substitute for the CA’s own monitoring.
Participants
yulier.nunez@anf.es chrome-root-program@google.com agwa-bugs@mm.beanwood.com
Related Bugzilla IDs Mentioned
Similar Local Cases
#2049012 ASSIGNED Ccadb Disclosure Issue Repository Issue Incident Audit Document Opened 2026-06-19 Still Open · 69% similar
FNMT: Inaccuracy in CRL URL in CCADB
#1969842 RESOLVED Ca Documents Incident Opened 2025-06-02 · Closed 2025-07-16 · 67% similar
ANF AC: Finding #1 ETSI Audit - Missing log retention period in Terms and Conditions v1.9
#2047579 ASSIGNED Incident Audit Finding Audit Delay Remediation Tracking Opened 2026-06-15 Still Open · 66% similar
ANF AC: 2026 Audit Report Finding 1 out of 3
#2047580 ASSIGNED Repository Issue Policy Document Issue Audit Finding Ccadb Disclosure Issue Opened 2026-06-15 Still Open · 64% similar
ANF AC: 2026 Audit Report Finding 2 out of 3
#1941675 RESOLVED Ca Documents Incident Opened 2025-01-14 · 64% similar
Certum root lists a Microsec CPS in AllCertificateRecordsCSVFormatv2
#2050850 ASSIGNED Ccadb Disclosure Issue Repository Issue Externally Reported Incident Opened 2026-06-26 Still Open · 59% similar
Asseco DS / Certum: HTTP 404 returned by CRL Distribution Point URLs for six pre-inclusion Root CAs
#2025597 RESOLVED Incident Opened 2026-03-23 · Closed 2026-05-18 · 59% similar
IdenTrust: Delay in updating a Bug 2016585 - Next update
#2010885 RESOLVED Ccadb Disclosure Issue Opened 2026-01-16 · Closed 2026-03-05 · 58% similar
Sectigo: Inaccuracy of CCADB-Disclosed URL for eIDAS CP/CPS

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action