D-Trust self-reported OCSP responder certificate policy OID incident; bug closed INVALID
D-Trust self-reported an incident involving delegated OCSP responder certificates that contained certificate policy OIDs intended for publicly trusted TLS certificates, including the CA/Browser Forum DV policy OID and an ETSI DV policy OID. D-Trust said its technical investigation confirmed the facts in the third-party report and later completed a fuller review of the affected certificates. In its closure request, D-Trust said it identified three OCSP responder certificates in scope and that all of them were issued before 15 September 2023. D-Trust concluded that, based on the requirements applicable at the time of issuance, the certificates were not issued in violation of the CA/Browser Forum Baseline Requirements or D-Trust's governing documents. CCADB then issued a final call for comments and said the bug would be closed as INVALID if no further questions were raised; the bug is now RESOLVED with resolution INVALID.
- One affected OCSP responder certificate was issued.
- Two additional affected OCSP responder certificates were issued.
- BR 2.0.0 became effective and introduced a mandatory prohibition on certificatePolicies in OCSP responder certificates.
- A third-party report alleged that D-Trust OCSP Signer certificates incorrectly included public TLS policy OIDs.
- D-Trust completed its investigation and requested closure, saying the certificates were not issued in violation of the applicable requirements.
- D-Trust — D-Trust opened a preliminary incident report, confirmed the report's factual allegations, and said it was still assessing BR, CP/CPS, and ETSI compliance.
- D-Trust — D-Trust said it found three affected OCSP responder certificates, concluded they were not issued in violation of the applicable requirements, and requested closure.
- CCADB representative — CCADB issued a final call for comments and said the bug would be closed as INVALID if no further questions were raised.