Buypass: Intermediate certificates not listed in audit reports
This case concerns Buypass intermediate certificates that were not listed in audit reports. Buypass said it became aware of the issue through a discussion on mozilla.dev.security.policy and then investigated it, concluding that revocation was the only feasible option. Buypass initiated investigation into whether the intermediate certificates were still used and stated that it would prepare a revocation plan. Buypass decided to revoke 6 intermediate certificates on October 12, 2019, and later reported that it had revoked those 6 but had not yet decided a revocation date for the last 2. Buypass subsequently set the revocation date for the last two intermediate certificates to Tuesday 21 April (year not stated in the thread excerpt). A separate bug (1598319) was referenced as tracking the revocation of the remaining certificates, and the thread notes that this bug could be resolved given that separate tracking. The bug was resolved with resolution FIXED.
- Buypass became aware of the intermediate-certificate audit-report omission issue via a mozilla.dev.security.policy posting.
- Buypass revoked 6 intermediate certificates.
- Buypass set a revocation date for the last two intermediate certificates.
- Buypass — Buypass opened the incident report describing 8 intermediate certificates not listed in audit reports and outlined investigation and planned remediation.
- Fastly representative — Ryan Sleevi asked when Buypass would provide an update on the investigation and noted the lack of a clear remediation timeline.
- Buypass — Buypass stated it decided to revoke 6 intermediate certificates on October 12 and that two others were still under investigation, listing their crt.sh URLs.
- Buypass — Buypass reported it had revoked 6 intermediate certificates and still had not decided a revocation date for the last 2.
- Buypass — Buypass reported it set the revocation date for the last two intermediate certificates to Tuesday 21 April.
- Community commenter — Ryan Sleevi referenced Bug 1598319 as tracking the revocation and discussed the root-cause understanding from the incident report.
- Fastly representative — Wthayer stated that, since revocation was tracked in a separate bug, this bug could be resolved.