← Buypass cases
Bugzilla #1598319
Certificate Problem Report
Buypass: intermediate certificates not revoked within BR time period
RESOLVED
FIXED
Buypass
AI Summary
Buypass reported an incident involving two intermediate certificates that were not revoked within the required BR time period. The issue was identified through discussions on the Mozilla security policy mailing list and was linked to a previous bug report. After analyzing OCSP requests, Buypass managed to reduce the potential impact on customers and set a revocation date for the certificates. The certificates were ultimately revoked on April 21, 2020, and the remediation process was confirmed complete by May 19, 2020.
Chronology
- First incident reported regarding intermediate certificates not listed in audit reports.
- Six of the eight intermediate certificates were revoked.
- Clarification on expectations for CA actions regarding intermediate certificates.
- Analysis of OCSP requests led to a plan for revocation.
- The two intermediate certificates were revoked.
- Remediation confirmed complete.
Participants
Mads Henriksveen
Ryan Sleevi
W. Thayer
External References
Similar Local Cases
Buypass: Intermediate certificates not listed in audit reports
Buypass: Failure to revoke PSD2 QWACs within mandated 5 days
Buypass: Illegal Business Category in a PSD2 QWAC
Buypass: PSD2 QWAC with RSA modulus not divisible by 8
Buypass: Missing NCA identifier in cabfOrganizationIdentifier in PSD2 QWACs
Buypass: Insufficient Serial Number Entropy
Buypass: TLS certificates with incorrect Subject attribute order
Buypass: Domain validation method using not allowed domain contact