D-Trust OCSP responder certificates allegedly include public TLS policy OIDs
This case concerns a third-party report that D-Trust GmbH issued OCSP Signer certificates that incorrectly assert certificate policy OIDs intended for publicly trusted TLS server certificates, including the CA/Browser Forum Domain Validated policy OID and an ETSI TLS/SSL Domain Validation policy OID. D-Trust says its technical investigation confirmed the facts described in the report. The company also said it had not yet concluded whether the certificate profile is non-compliant with the CA/Browser Forum Baseline Requirements. D-Trust noted that the OCSP-responder certificates were issued before BR 2.0.0 became effective on 2023-09-15, and that its review of the applicable BR, CP/CPS, and ETSI requirements was ongoing. The bug remains assigned, and no resolution is recorded in the thread provided.
- BR 2.0.0 became effective, according to D-Trust's comment.
- Third-party report alleged D-Trust OCSP Signer certificates contained public TLS policy OIDs.
- D-Trust — D-Trust opened a preliminary incident report, confirmed the report's factual allegations, and said it was still assessing BR, CP/CPS, and ETSI compliance.