-
Notifications
You must be signed in to change notification settings - Fork 19
Description
Mozilla policy requires that a CA be able to serve validation information for precertificates - see https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/policy/#54-precertificates, but no timeframe is specified for when OCSP responses must be available. My understanding is that many CAs distribute OCSP responses via CDN, and depending on the CDN's infrastructure and where you are in the world, you might get an "unauthorized" response to an OCSP request.
A few bugs have been filed for OCSP "unauthorized" responses for certificates / precertificates. See https://bugzilla.mozilla.org/show_bug.cgi?id=1903823 and https://bugzilla.mozilla.org/show_bug.cgi?id=1905419. For cross-reference, some OCSP data is available through OCSP Watch, https://sslmate.com/labs/ocsp_watch/ and https://crt.sh. One proposal is that CA operators be given 15 minutes between the CT logging of the precertificate and having an OCSP response available. A result of this proposed 15-minute initial window would be to clarify the issue for compliance purposes.