← D-TRUST cases
Bugzilla #2056223 Ca Certificate Compliance Incident Externally Reported Incident Policy Document Issue Opened By Ca

D-Trust OCSP responder certificates allegedly include public TLS policy OIDs

ASSIGNED D-TRUST
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns a third-party report that D-Trust GmbH issued OCSP Signer certificates that incorrectly assert certificate policy OIDs intended for publicly trusted TLS server certificates, including the CA/Browser Forum Domain Validated policy OID and an ETSI TLS/SSL Domain Validation policy OID. D-Trust says its technical investigation confirmed the facts described in the report. The company also said it had not yet concluded whether the certificate profile is non-compliant with the CA/Browser Forum Baseline Requirements. D-Trust noted that the OCSP-responder certificates were issued before BR 2.0.0 became effective on 2023-09-15, and that its review of the applicable BR, CP/CPS, and ETSI requirements was ongoing. The bug remains assigned, and no resolution is recorded in the thread provided.

Model: gpt-5.4-mini Generated: 2026-07-26 06:23 UTC Confidence: 0.91 1 comment
Chronology
  1. BR 2.0.0 became effective, according to D-Trust's comment.
  2. Third-party report alleged D-Trust OCSP Signer certificates contained public TLS policy OIDs.
Thread Activity
  1. D-Trust — D-Trust opened a preliminary incident report, confirmed the report's factual allegations, and said it was still assessing BR, CP/CPS, and ETSI compliance.
Participants
D-Trust
External References
Similar Local Cases
#1918427 RESOLVED Ca Certificate Compliance Incident Closure Request Opened 2024-09-12 · Closed 2024-10-11 · 80% similar
D-Trust: Non-compliance of issued root and intermediate S/MIME certificates
#2056663 ASSIGNED Ca Certificate Compliance Externally Reported Incident Problem Reporting Failure Opened By Ca Opened 2026-07-21 Still Open · 69% similar
DigiCert: EVG CA profile compliance
#2053131 ASSIGNED Ca Certificate Compliance Incident Externally Reported Incident Problem Reporting Failure Opened 2026-07-07 Still Open · 69% similar
TunTrust: OCSP responder "Unknown" of one Pre-certificate
#1367842 RESOLVED Ca Certificate Compliance Incident Opened 2017-05-25 · Closed 2023-02-22 · 69% similar
TurkTrust: Non-audited, non-technically-constrained intermediate certs
#1620727 RESOLVED Ca Certificate Compliance Incident Opened 2020-03-07 · Closed 2023-02-22 · 69% similar
Microsoft DSRE PKI: OCSP responders found to respond signed by the default CA when passed an invalid issuer in request
#1398246 RESOLVED Ca Certificate Compliance Incident Opened 2017-09-08 · Closed 2023-02-22 · 69% similar
Consorci AOC: Non-BR-Compliant OCSP Responders
#2049237 ASSIGNED Ca Certificate Compliance Incident Externally Reported Incident Revocation Issue Opened 2026-06-22 Still Open · 68% similar
HARICA: Continued issuance and refusal to revoke TLS certificates for EU-sanctioned blocked entities (Sberbank, VTB, KAMAZ, ANO Dialog)
#2007116 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Externally Reported Incident Opened 2025-12-19 Still Open · 67% similar
D-Trust: CRL URL Disclosure

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action