rejects forged Good OCSP responses signed by same-issuer responder certificates that lack delegated OCSPSigning authorization under RFC 6960 section 4.2.2.2. public PR #378 merged on 2026-04-24.
PR opened by
@mholt
PR state observed
closed; GitHub merged: true; 2026-09-24
PR observation basis
Public PR metadata recorded in the 2026-09-24 evidence audit; not a live status feed.
Contribution boundary
Report-associated upstream work; @1seal code authorship is not claimed. Credit, where recorded, is a separate fact.
ocsp: add delegated responder authorization regression test
merged
details
Finding IDs
F-CADDY-CERTMAGIC-OCSP-001
Status
merged
Reported date
Rationale
adds regression coverage for the delegated OCSP responder authorization path fixed for F-CADDY-CERTMAGIC-OCSP-001, including rejection of same-issuer non-OCSPSigning responders.
PR opened by
@1seal
PR state observed
closed; GitHub merged: true; 2026-09-24
PR observation basis
Public PR metadata recorded in the 2026-09-24 evidence audit; not a live status feed.
Contribution boundary
@1seal opened this PR; this alone does not establish sole code authorship.
This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.