← Izenpe S.A. cases
Bugzilla #1596744 Delayed Revocation Incident

Izenpe: Intermediate CA certificates not listed in audit report

RESOLVED FIXED Izenpe S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Izenpe reported that its CCADB Audit Letter Validation (ALV) results showed a problem: SHA1 version CA certificates (including subCA and root CA certificates) were not included in the audit report, even though CA certificates were covered. After clarifications and internal discussion, Izenpe decided to prepare a plan to revoke all affected certificates. Izenpe stated that it had two sets of subCAs: SSL/TLS subCAs and non-SSL/TLS subCAs, and that three SSL/TLS subCAs would be revoked on Friday 22 November. For the remaining four non-SSL/TLS subCAs, Izenpe said it was analyzing customer impact (including qualified signatures) and considered adding them to OneCRL rather than revoking immediately. Mozilla’s Ryan Sleevi noted that a clear revocation plan is expected to bring the CA back into compliance, and that root programs cannot grant exceptions to the Baseline Requirements. Izenpe then reported that all SSL/TLS subCAs had been revoked, and opened Bug 1598608 to address not revoking four pending subCAs within the Baseline Requirements time period. Finally, Izenpe reported that, following the defined timeline, all pending subCAs were revoked, and a later comment indicated remediation was complete. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 20:17 UTC Revised: 2026-06-16 19:12 UTC Confidence: 0.86 6 comments
Chronology
  1. Izenpe became aware of the audit-report omission via CCADB Audit Letter Validation (ALV) results and began planning revocation.
  2. Izenpe revoked the SSL/TLS subCAs identified as affected.
  3. Izenpe revoked the remaining pending subCAs after completing its defined revocation timeline.
Thread Activity
  1. Izenpe S.A. — Oscar Garcia said Izenpe became aware of the issue via CCADB ALV results, initially misinterpreted it, and then decided to prepare a plan to revoke all affected certificates.
  2. Izenpe S.A. — Oscar Garcia described two groups of subCAs, stated three SSL/TLS subCAs would be revoked on 22 November, and said the remaining four non-SSL/TLS subCAs were pending due to impact analysis and possible OneCRL use.
  3. Community commenter — Ryan Sleevi emphasized that a clear revocation plan is expected for Baseline Requirements compliance and referenced Mozilla guidance on incident response and revocation.
  4. Izenpe S.A. — Oscar Garcia reported that all SSL/TLS subCAs had been revoked and that Bug 1598608 was opened for the four pending subCAs not revoked within the BR-defined time period.
  5. Izenpe S.A. — Oscar Garcia reported that all pending subCAs were revoked in accordance with the defined timeline.
  6. Fastly representative — W. Thayer stated it appeared all questions were answered and remediation was complete.
Participants
Izenpe S.A. Community commenter Fastly representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1598608 RESOLVED Delayed Revocation Incident Opened 2019-11-22 · Closed 2023-02-22 · 100% similar
Izenpe: intermediate certificates not revoked within BR time period
#1656487 RESOLVED Delayed Revocation Opened 2020-07-31 · Closed 2023-02-22 · 83% similar
Izenpe: Failure to revoke within 5 days
#2058294 UNCONFIRMED Ca Certificate Compliance Incident Self Reported Incident Delayed Revocation Opened 2026-07-27 Still Open · 71% similar
SDAIA: Delayed Revocation related to Bugzilla #2056942
#1877388 RESOLVED Delayed Revocation Incident Self Reported Incident Opened 2024-01-30 · Closed 2025-03-14 · 71% similar
Telekom Security: Revocation delay for TLS certificates with basicConstraints not marked as critical
#1792111 RESOLVED Delayed Revocation Incident Opened 2022-09-22 · Closed 2023-02-22 · 70% similar
IdenTrust: Expired CRLs
#1743943 RESOLVED Delayed Revocation Incident Opened 2021-12-02 · Closed 2023-06-02 · 70% similar
Amazon Trust Services: Delayed Revocation of Subordinate CA
#1719920 RESOLVED Delayed Revocation Incident Opened 2021-07-09 · Closed 2023-02-22 · 69% similar
Amazon Trust Services: Revocation Time for Intermediate Certificates
#1599571 RESOLVED Delayed Revocation Opened 2019-11-26 · Closed 2023-02-22 · 68% similar
TrustCor: Non-revocation of CA certificates within 7 days

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action