DigiCert third-party CPR about delayed OCSP response availability; incident report closed after remediation
This case concerns DigiCert’s handling of a third-party Certificate Problem Report about OCSP responses that were not available within the 15-minute window required by TLS Baseline Requirements Section 4.9.9. DigiCert said the report involved two newly issued certificates and that the issue was temporary OCSP status-response availability at the CDN edge, not misissuance or revocation. DigiCert explained that authoritative responses reached the OCSP origin on time, but CDN pull-cache behavior and independently caching PoPs could leave stale responses visible externally past the deadline. In response, DigiCert reduced the OCSP origin TTL from 10 minutes to 5 minutes and augmented monitoring to measure edge availability. DigiCert later said all disclosed action items were completed and requested closure of the incident report. The bug is now resolved with a FIXED resolution, and CCADB had issued a final call for comments before closure.
- A third party first observed OCSP responses that were not available within 15 minutes of issuance.
- DigiCert reduced the OCSP origin TTL from 10 minutes to 5 minutes and said the non-compliance ended.
- DigiCert said all action items were completed and requested closure.
- The bug was resolved with FIXED.
- DigiCert — Filed a preliminary incident report saying OCSP responses were sometimes unavailable within 15 minutes of certificate or precertificate issuance and citing BR Section 4.9.9.
- DigiCert — Submitted the full incident report describing the third-party CPR, the investigation, the CDN caching explanation, and the TTL reduction.
- DigiCert — Posted a closure summary saying all disclosed action items were completed and requesting closure of the incident report.
- CCADB representative — Issued a final call for comments or questions and said the report would be closed on approximately 2026-08-11.