← D-TRUST cases
Bugzilla #2056223 Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Policy Document Issue

D-Trust self-reported OCSP responder certificate policy OID incident; bug closed INVALID

RESOLVED INVALID D-TRUST
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

D-Trust self-reported an incident involving delegated OCSP responder certificates that contained certificate policy OIDs intended for publicly trusted TLS certificates, including the CA/Browser Forum DV policy OID and an ETSI DV policy OID. D-Trust said its technical investigation confirmed the facts in the third-party report and later completed a fuller review of the affected certificates. In its closure request, D-Trust said it identified three OCSP responder certificates in scope and that all of them were issued before 15 September 2023. D-Trust concluded that, based on the requirements applicable at the time of issuance, the certificates were not issued in violation of the CA/Browser Forum Baseline Requirements or D-Trust's governing documents. CCADB then issued a final call for comments and said the bug would be closed as INVALID if no further questions were raised; the bug is now RESOLVED with resolution INVALID.

Model: gpt-5.4-mini Generated: 2026-07-26 06:23 UTC Revised: 2026-08-09 07:01 UTC Confidence: 0.96 3 comments
Chronology
  1. One affected OCSP responder certificate was issued.
  2. Two additional affected OCSP responder certificates were issued.
  3. BR 2.0.0 became effective and introduced a mandatory prohibition on certificatePolicies in OCSP responder certificates.
  4. A third-party report alleged that D-Trust OCSP Signer certificates incorrectly included public TLS policy OIDs.
  5. D-Trust completed its investigation and requested closure, saying the certificates were not issued in violation of the applicable requirements.
Thread Activity
  1. D-Trust — D-Trust opened a preliminary incident report, confirmed the report's factual allegations, and said it was still assessing BR, CP/CPS, and ETSI compliance.
  2. D-Trust — D-Trust said it found three affected OCSP responder certificates, concluded they were not issued in violation of the applicable requirements, and requested closure.
  3. CCADB representative — CCADB issued a final call for comments and said the bug would be closed as INVALID if no further questions were raised.
Participants
D-Trust CCADB representative
External References
Similar Local Cases
#2007116 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Ccadb Disclosure Issue Opened 2025-12-19 · Closed 2026-09-03 · 97% similar
D-Trust: CRL URL Disclosure
#2037000 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-05-05 Still Open · 97% similar
D-Trust: Missing Pre-Sign Linting for S/MIME Issuing CAs
#2012511 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2026-01-26 · Closed 2026-04-19 · 94% similar
D-Trust: CRL HTTP Media Type
#2029013 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Validation Issue Opened 2026-04-02 Still Open · 90% similar
D-Trust: Missing Pre-Signing Linting for TLS Issuance
#2010600 RESOLVED Incident Opened 2026-01-15 · Closed 2026-02-27 · 88% similar
D-Trust: CRLs of CAs issuing CA certificates exceed the maximum validity period
#1924385 RESOLVED Ca Certificate Compliance Revocation Issue Closure Request Opened 2024-10-13 · Closed 2025-07-16 · 87% similar
D-Trust: Missed Revocation of TLS certificates affected by Bugzilla 1884714
#2009149 RESOLVED Incident Opened 2026-01-08 · Closed 2026-08-05 · 87% similar
D-Trust: Expired certificate provided on the CA TLS test website for demonstration of valid certificates
#1976837 RESOLVED Incident Opened 2025-07-11 · Closed 2025-08-19 · 85% similar
D-Trust: Defective certificate incident reporting form

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action