Izenpe: Intermediate CA certificates not listed in audit report
Izenpe reported that its CCADB Audit Letter Validation (ALV) results showed a problem: SHA1 version CA certificates (including subCA and root CA certificates) were not included in the audit report, even though CA certificates were covered. After clarifications and internal discussion, Izenpe decided to prepare a plan to revoke all affected certificates. Izenpe stated that it had two sets of subCAs: SSL/TLS subCAs and non-SSL/TLS subCAs, and that three SSL/TLS subCAs would be revoked on Friday 22 November. For the remaining four non-SSL/TLS subCAs, Izenpe said it was analyzing customer impact (including qualified signatures) and considered adding them to OneCRL rather than revoking immediately. Mozilla’s Ryan Sleevi noted that a clear revocation plan is expected to bring the CA back into compliance, and that root programs cannot grant exceptions to the Baseline Requirements. Izenpe then reported that all SSL/TLS subCAs had been revoked, and opened Bug 1598608 to address not revoking four pending subCAs within the Baseline Requirements time period. Finally, Izenpe reported that, following the defined timeline, all pending subCAs were revoked, and a later comment indicated remediation was complete. The bug is marked RESOLVED with resolution FIXED.
- Izenpe became aware of the audit-report omission via CCADB Audit Letter Validation (ALV) results and began planning revocation.
- Izenpe revoked the SSL/TLS subCAs identified as affected.
- Izenpe revoked the remaining pending subCAs after completing its defined revocation timeline.
- Izenpe S.A. — Oscar Garcia said Izenpe became aware of the issue via CCADB ALV results, initially misinterpreted it, and then decided to prepare a plan to revoke all affected certificates.
- Izenpe S.A. — Oscar Garcia described two groups of subCAs, stated three SSL/TLS subCAs would be revoked on 22 November, and said the remaining four non-SSL/TLS subCAs were pending due to impact analysis and possible OneCRL use.
- Community commenter — Ryan Sleevi emphasized that a clear revocation plan is expected for Baseline Requirements compliance and referenced Mozilla guidance on incident response and revocation.
- Izenpe S.A. — Oscar Garcia reported that all SSL/TLS subCAs had been revoked and that Bug 1598608 was opened for the four pending subCAs not revoked within the BR-defined time period.
- Izenpe S.A. — Oscar Garcia reported that all pending subCAs were revoked in accordance with the defined timeline.
- Fastly representative — W. Thayer stated it appeared all questions were answered and remediation was complete.