Skip to content

OCSP response issuance latency for certificates/pre-certificates #280

@BenWilson-Mozilla

Description

@BenWilson-Mozilla

Mozilla policy requires that a CA be able to serve validation information for precertificates - see https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/policy/#54-precertificates, but no timeframe is specified for when OCSP responses must be available. My understanding is that many CAs distribute OCSP responses via CDN, and depending on the CDN's infrastructure and where you are in the world, you might get an "unauthorized" response to an OCSP request.

A few bugs have been filed for OCSP "unauthorized" responses for certificates / precertificates. See https://bugzilla.mozilla.org/show_bug.cgi?id=1903823 and https://bugzilla.mozilla.org/show_bug.cgi?id=1905419. For cross-reference, some OCSP data is available through OCSP Watch, https://sslmate.com/labs/ocsp_watch/ and https://crt.sh. One proposal is that CA operators be given 15 minutes between the CT logging of the precertificate and having an OCSP response available. A result of this proposed 15-minute initial window would be to clarify the issue for compliance purposes.

Metadata

Metadata

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions