← Amazon Trust Services cases
Bugzilla #1525710 Ca Certificate Compliance Self Reported Incident

Amazon Trust Services: Test revoked certificates with invalid validity period

RESOLVED FIXED Amazon Trust Services
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Amazon Trust Services disclosed that it had issued “test revoked” certificates intended for software vendors to test revoked certificates. The certificates were created with an incorrect validity period of 39 months and an incorrect subject that made them appear to be EV certificates. Amazon stated that after running cablint on the certificates on 2/1/2019, it discovered that the revoked certificates were incorrectly formatted and identified as EV certs with 39 months validity. Amazon said it would not issue test revoked certificates with an incorrect validity or subject again, and reported remediation steps including updating the script to default test revoked certificates to 13 months and adjusting the guardrail so these test certs cannot exceed 825 days, and updating the commands template to use the correct subject. Amazon also described process changes for offline issuance, including requiring artifact review before and after signing against its CPS and adding linting both prior to and following issuance. A Fastly participant later commented that remediation appeared complete. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 15:26 UTC Revised: 2026-06-16 18:02 UTC Confidence: 0.86 4 comments
Chronology
  1. Amazon Trust Services created five test revoked certificates and revoked them about a minute later.
  2. Amazon Trust Services ran cablint during post-ceremony validation and discovered the revoked certificates were incorrectly formatted (EV-like subject and 39-month validity).
  3. Amazon Trust Services provided crt.sh links listing the problematic certificates.
  4. Amazon Trust Services explained the cause and described updates to its offline issuance process and linting/artifact review steps.
  5. A participant stated that remediation appeared complete.
Thread Activity
  1. Community commenter — Ryan Sleevi opened the disclosure describing the incorrect 39-month validity and EV-like subject for test revoked certificates, how cablint discovered the issue on 2/1/2019, and the remediation steps Amazon took.
  2. Community commenter — Trevoli provided a list of the problematic certificates via crt.sh links.
  3. Community commenter — Trevoli explained the underlying cause (template/guardrail not updated for Ballot 193 changes and missing artifact review in offline issuance) and described process updates to review artifacts and lint before and after issuance.
  4. Community commenter — Wayne Thayer commented that remediation is complete.
Participants
Community commenter DigiCert Fastly representative
Similar Local Cases
#1569266 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-07-26 · Closed 2023-02-22 · 100% similar
Amazon Trust Services: No Space In Private Organization
#1746945 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-12-20 · Closed 2023-02-22 · 90% similar
Amazon Trust Services: Missing CAA Check For Test Website Certificates
#1574594 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-08-16 · Closed 2023-02-22 · 87% similar
Amazon Trust Services: Revoked Sample Certs - No SANs
#1579950 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-09-09 · Closed 2022-11-14 · 86% similar
QuoVadis: OCSP handling of Certificate Transparency Pre-certs
#1391056 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-08-16 · Closed 2023-02-22 · 86% similar
NetLock: Non-BR-Compliant Certificate Issuance
#1538638 RESOLVED Ca Certificate Compliance Self Reported Incident Revocation Issue Opened 2019-03-25 · Closed 2023-02-22 · 86% similar
Firmaprofesional: AC Firmaprofesional - INFRAESTRUCTURA insufficient serial number entropy
#2009525 RESOLVED Self Reported Incident Opened 2026-01-09 · Closed 2026-03-08 · 86% similar
Amazon Trust Services: Additional CRL Characteristics Desired in CP/CPS
#1575022 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2019-08-19 · Closed 2023-02-22 · 85% similar
Sectigo: EV SSL Certificates with incorrect subject details.

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action