← Apple Inc. cases
Bugzilla #1588001 Certificate Problem Report

Apple: OCSP responders return responses with incorrect issuer

RESOLVED FIXED Apple Inc.
AI Summary

Apple's OCSP responders were found to return signed responses with incorrect issuers, which was reported on October 3, 2019. An investigation revealed that when the OCSP service could not process a request, it defaulted to signing responses with a generic OCSP responder. Apple initiated a fix to ensure that responses are signed by the correct issuer and communicated the issue to relevant stakeholders, including root vendors. The fix was rolled out by October 18, 2019, and no non-compliant certificates were issued during the incident.

Model: gpt-4o-mini Generated: 2026-06-13 15:12 UTC Confidence: 0.90
Chronology
  1. Problem report received regarding OCSP responses.
  2. Investigation began and fix rollout started.
  3. Fix for OCSP service completed.
Participants
certification_authority@apple.com ryan.sleevi@gmail.com
External References
Similar Local Cases
#1677234 RESOLVED Certificate Problem Report Opened 2020-11-13 · Closed 2023-02-22 · 64% similar
Apple: OCSP availability 2020-11-12
#1659316 RESOLVED Certificate Problem Report Opened 2020-08-16 · Closed 2023-02-22 · 64% similar
Apple: EV Certificate Approver Authorization
#1771398 RESOLVED Certificate Problem Report Opened 2022-05-26 · Closed 2023-02-22 · 60% similar
Apple: OCSP responders return ‘unknown’ for valid S/MIME and TLS certificates
#1955365 RESOLVED Certificate Problem Report Opened 2025-03-20 · Closed 2025-05-19 · 57% similar
Apple: Public Key Reuse
#1843676 RESOLVED Certificate Problem Report Opened 2023-07-15 · Closed 2023-09-22 · 57% similar
Apple: Revocation Delay for TLS certificates issued outside the TTL of the CAA record
#1841534 RESOLVED Certificate Problem Report Opened 2023-07-03 · Closed 2023-08-30 · 57% similar
Apple: TLS certificates issued outside the TTL of the CAA record
#1793210 RESOLVED Certificate Problem Report Opened 2022-09-30 · Closed 2022-11-14 · 57% similar
Apple: CRLs for dormant CAs will not be populated in CCADB
#1556906 RESOLVED Certificate Problem Report Opened 2019-06-05 · Closed 2023-02-22 · 57% similar
DigiCert: Apple: Non-compliant Common Name Length

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action