Buypass: intermediate certificates not revoked within BR time period
This case concerns Buypass intermediate certificates that were not revoked within the BR time period. Buypass became aware of the issue through a discussion on mozilla.dev.security.policy and later clarification from Ryan Sleevi, and created an incident report for two intermediate certificates that were not listed in audit reports and should have been revoked. Buypass initially revoked 6 of 8 intermediate certificates on 2019-11-12, but delayed revocation of the remaining 2 because analysis of OCSP requests indicated they were still extensively used, prompting a more thorough investigation to avoid customer impact. Buypass performed further OCSP request analysis, identified high-volume customer services still using the old intermediates, instructed those customers to replace the intermediates, and reduced OCSP request volume to an acceptable level. Buypass then set a revocation date for the two intermediate certificates to 2020-04-21, and reported that the two intermediate certificates were revoked on that date. A Fastly participant later stated that remediation was complete.
- Buypass revoked 6 of 8 intermediate certificates.
- Buypass revoked the remaining two intermediate certificates.
- Buypass — Created the incident report describing two intermediate certificates not listed in audit reports and not revoked within the BR time period, including the background and planned investigation.
- Buypass — Reported OCSP request analysis, customer outreach to replace old intermediates, reduced OCSP volume, and set the revocation date to 2020-04-21.
- Buypass — Reported that the two intermediate certificates were revoked.
- Fastly representative — Stated that it appears all questions have been answered and remediation is complete.