Handle id-pkix-ocsp-nocheck in OCSP responder verification
details
- Finding IDs
- F-AWSLC-OCSP-RESPONDER-REVOC-0
- Status
- fixed/documented publicly
- Reported via
- AWS Security
- Note
- AWS determined the report did not present a security vulnerability to AWS-LC or s2n-tls, but released public aws-lc PR #3169 on 2026-04-30 to handle id-pkix-ocsp-nocheck in delegated OCSP responder verification. AWS also released s2n-tls PR #5859 on 2026-05-01 to document that OCSP_basic_verify() does not verify OCSP delegated responder certificates and that this is caller configuration responsibility.
F-AWSLC-OCSP-RESPONDER-REVOC-0: Verification failures. The report concerns delegated responder revocation policy; AWS treated it as a bug/documentation update, not a security vulnerability. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-AWSLC-OCSP-RESPONDER-REVOC-0
Security area (1seal assessment): Authorization. Delegated OCSP responder authorization depends on the configured revocation policy and nocheck exception. AWS treated this as a bug/documentation update, not a security vulnerability. Reviewed 24 Sep 2026.