Skip to content

fix(sdk): Report a good OCSP response outside its window as unknown - #2741

Open
ssanthosh wants to merge 1 commit into
mainfrom
ssanthosh/cai-13689
Open

ssanthosh wants to merge 1 commit into
mainfrom
ssanthosh/cai-13689

Conversation

@ssanthosh

Copy link
Copy Markdown
Contributor

Changes in this pull request

Fixes #2644
Changes are similar to #2664

Problem

An OCSP response with certStatus = good whose validity window ([thisUpdate, nextUpdate]) does not cover the reference instant was misclassified as signingCredential.ocsp.revoked. Because check_ocsp_status turns that status into CertificateTrustError::CertificateNotTrusted, a certificate the responder explicitly said was not revoked was treated as untrusted. A clock skew of a single second between the responder and the validator was enough to flip a fresh good into a false revocation.

Fix

In the CertStatus::Good branch of OcspResponse::from_der_checked, an out-of-window response now logs signingCredential.ocsp.unknown (informational) instead of signingCredential.ocsp.revoked (failure). "Good outside the window" is an inconclusive outcome, not a revocation, so certificate trust is no longer failed on it.

Tests added

Updated the validity unit test (which previously asserted the buggy REVOKED behavior) to assert an out-of-window good response now yields signingCredential.ocsp.unknown, produces no validation error, and is logged as informational.

Checklist

  • This PR represents a single feature, fix, or change.
  • All applicable changes have been documented.
  • Any TO DO items (or similar) have been entered as GitHub issues and the link to that issue has been included in a comment.

@codspeed

codspeed Bot commented Sep 28, 2026

Copy link
Copy Markdown

Merging this PR will not alter performance

✅ 30 untouched benchmarks
⏩ 64 skipped benchmarks1


Comparing ssanthosh/cai-13689 (be8918e) with main (a7021ff)

Open in CodSpeed

Footnotes

  1. 64 benchmarks were skipped, so the baseline results were used instead. If they were deleted from the codebase, click here and archive them to remove them from the performance reports. ↩

@tmathern tmathern left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Does this change matches the spec and spirit of the spec from https://spec.c2pa.org/specifications/specifications/2.4/specs/C2PA_Specification.html#ocsp_online (towards the bottom of the section, just above 15.10)?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

OCSP certStatus=good outside the applicable time window is reported as signingCredential.ocsp.revoked

2 participants