1sealsemantic last-mile verification

Research / Finding

Handle id-pkix-ocsp-nocheck in OCSP responder verification

F-AWSLC-OCSP-RESPONDER-REVOC-0

Public snapshot: 26 Sep 2026. Status, releases and attribution belong to each source below; none is inferred from another record.

Read the evidence · View in research browse

Recorded evidence

—score not recorded
aws/aws-lcReported fixaws/aws-lc

Handle id-pkix-ocsp-nocheck in OCSP responder verification

fixed/documented publicly
details
Finding IDs
F-AWSLC-OCSP-RESPONDER-REVOC-0
Status
fixed/documented publicly
Reported via
AWS Security
Note
AWS determined the report did not present a security vulnerability to AWS-LC or s2n-tls, but released public aws-lc PR #3169 on 2026-04-30 to handle id-pkix-ocsp-nocheck in delegated OCSP responder verification. AWS also released s2n-tls PR #5859 on 2026-05-01 to document that OCSP_basic_verify() does not verify OCSP delegated responder certificates and that this is caller configuration responsibility.

F-AWSLC-OCSP-RESPONDER-REVOC-0: Verification failures. The report concerns delegated responder revocation policy; AWS treated it as a bug/documentation update, not a security vulnerability. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.

Mechanism source for F-AWSLC-OCSP-RESPONDER-REVOC-0

Security area (1seal assessment): Authorization. Delegated OCSP responder authorization depends on the configured revocation policy and nocheck exception. AWS treated this as a bug/documentation update, not a security vulnerability. Reviewed 24 Sep 2026.

Clarify or correct this record privately. The email subject includes the finding ID. For an existing case, continue the agreed private thread. Do not post unpublished vulnerability details in public issues. Research disclosure policy.

How this page groups evidence

This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.