← DigiCert cases
Bugzilla #1398269 · Certificate Problem Report
DigiCert: Non-BR-Compliant OCSP Responders
DigiCert · RESOLVED
AI Summary
This case addresses issues with DigiCert's OCSP responders not complying with the Baseline Requirements (BRs). Specifically, the OCSP responders were found to incorrectly respond with a 'good' status for unissued certificates, violating section 4.9.10 of the BRs. The issue has been resolved, with updates indicating that the OCSP responder now correctly returns an 'unauthorized' error for unissued certificates.
Chronology
- Initial report of OCSP responder issues.
- Migration of OCSP responder completed, issue confirmed fixed.
Participants
Kathleen Wilson
Jeremy Rowley
Ben Wilson
Gervase Markham
Wayne Thayer
External References
Similar Local Cases
DigiCert: Symantec non-constrained/non-disclosed intermediate CA certificates
DigiCert / InfoCert: Insufficient Serial Number Entropy
DigiCert: no subject alternative name in Siemens certs
DigiCert: Microsoft: Incident report for Microsoft Dynamics incident
DigiCert: Certificate Issues Identified on the Mailing List
DigiCert: TI Trust Technologies Global CA issued certificate with no subject alternative name extension
DigiCert: Non-BR Compliant Certificates - missing CP/CPS OID
DigiCert: ECCE 001 issuing certificates without subject alternative name extension