← DocuSign (OpenTrust/Keynectis) cases
Bugzilla #1398247
Certificate Problem Report
DocuSign/Keynectis: Non-BR-Compliant OCSP Responders
RESOLVED
FIXED
DocuSign (OpenTrust/Keynectis)
AI Summary
The case involves DocuSign (OpenTrust/Keynectis) addressing issues with their OCSP responders that were found to be non-compliant with the Baseline Requirements (BRs). Specifically, the OCSP responders were responding with a 'good' status for unissued certificates, violating section 4.9.10 of the BRs. The CA has since updated its OCSP responder to be compliant and provided an incident report detailing the timeline and steps taken to rectify the issue. The case is now resolved.
Chronology
- Initial report of non-compliance with OCSP responders.
- OCSP responder updated to be BR-compliant.
- Incident report submitted detailing the timeline of events.
- New audit for the Certplus Class 2 Primary CA processed.
Participants
Kathleen Wilson
Erwann Abalea
Gervase Markham
Ryan Sleevi
Wayne Thayer
External References
Similar Local Cases
DocuSign/Keynectis: Non-BR-Compliant Certificate Issuance
DigiCert: Non-BR-Compliant OCSP Responders
SECOM: Non-BR-Compliant OCSP Responders
GlobalSign: Non-BR-Compliant Certificate Issuance -- RSA key smaller than 2048 bits
Disig: Non-BR-Compliant OCSP Responders
Visa: Non-BR-Compliant Certificate Issuance
DocuSign France - Internal names certificates under a technically-constrained subordinate CA
Consorci AOC: Non-BR-Compliant Certificate Issuance