I -- How your CA first became aware of the problem (e.g. via a problem report submitted to your Problem Reporting Mechanism, a discussion in mozilla.dev.security.policy, a Bugzilla bug, or internal self-audit), and the time and date.
Microsec received an iformation by phone, that 2 Microsec OCSP problems reported on the following site: https://sslmate.com/labs/ocsp_watch/
2023-07-18 19:55 CETII -- A timeline of the actions your CA took in response. A timeline is a date-and-time-stamped sequence of all relevant events. This may include events before the incident was reported, such as when a particular requirement became applicable, or a document changed, or a bug was introduced, or an audit was done.
III -- Whether your CA has stopped, or has not yet stopped, issuing certificates with the problem. A statement that you have will be considered a pledge to the community; a statement that you have not requires an explanation.
2022-12-16IV -- A summary of the problematic certificates. For each problem: number of certs, and the date the first and last certs with that problem were issued.
V -- The complete certificate data for the problematic certificates. The recommended way to provide this is to ensure each certificate is logged to CT and then list the fingerprints or crt.sh IDs, either in the report or as an attached spreadsheet, with one list per distinct problem.
We performed the initial investigation and we found the followingVI -- Explanation about how and why the mistakes were made or bugs introduced, and how they avoided detection until now.
-- the precertificate was created successfully
-- the precertificate transmitted to at least one log server successfully
-- the CA software could not reach the necessary number of log servers
-- the certificate issuance process was terminated with an error status
-- the TLS certificate was not issued
-- due to the improper error management flow installed in the CA software, the precertificate has not been added to the OCSP responders database.
The problem was caused by a configuration problem in the CA program
Immediate actionsVII -- List of steps your CA is taking to resolve the situation and ensure such issuance will not be repeated in the future, accompanied with a timeline of when your CA expects to accomplish these things.