TrustCor: Non-revocation of CA certificates within 7 days
This case concerns TrustCor’s subordinate CA certificates for its Enhanced Secure Email CA and Basic Secure Email CA programs. TrustCor stated that it became aware of discrepancies between its SSL-BR audit report and the standard WebTrust for CAs report, and that the subordinate CA certificates were not also listed in the SSL Baseline report due to a misunderstanding of the BRs and WebTrust for CAs SSL Baseline with Network Security standards. TrustCor explained that it initially considered the certificates out of scope because they were intended for S/MIME issuance only, but later recognized that the failure to disclose in both audits represented a violation of BR sections 8.1 and that revocation was expected within 24 hours, with failure to revoke within 7 days representing a further violation of BR section 4.9.1.2. TrustCor provided an explanation for why revocation did not occur within the initial 7-day window, stating it suspended the Enhanced Secure Email CA program during investigation and assessed the impact of immediate revocation on customers. TrustCor said it planned to formally revoke the Enhanced Secure Email CA on December 5, 2019 and the Basic Secure Email CA on April 1, 2020. The Enhanced Secure Email CA certificate was formally revoked on December 5, 2019, and TrustCor later stated the Basic Secure Email CA certificate was revoked as of April 1, 2020, with new CRLs and OCSP responses published. A Fastly participant stated on April 7, 2020 that remediation was complete.
- TrustCor began an initial investigation into discrepancies between audit reports for its email CA certificates.
- TrustCor suspended its Enhanced Secure Email CA program pending resolution.
- TrustCor completed a self-audit regarding whether the Email CA private keys signed any SSL certificates.
- TrustCor formally revoked the Enhanced Secure Email CA certificate.
- TrustCor formally revoked the Basic Secure Email CA certificate and published new CRLs and OCSP responses.
- Trustcorsystems representative — Neil Dunbar explained why revocations of the subordinate email CA certificates did not occur within the initial 7-day window after discovery of the disclosure discrepancy.
- Community commenter — Ryan Sleevi asked whether TrustCor planned to abide by its CP/CPS and Baseline Requirements and expressed concern about the incident response.
- Trustcorsystems representative — Neil Dunbar stated TrustCor did not intend to remain in violation and provided a tentative revocation and replacement schedule.
- Trustcorsystems representative — Neil Dunbar reported that the Enhanced Secure Email CA certificate was formally revoked as of December 5, 2019 17:10:18 UTC.
- Community commenter — Ryan Sleevi requested an analysis of factors that prevented timely revocation and remediation actions to prevent future delays, referencing a Mozilla incident response wiki page.
- Trustcorsystems representative — Neil Dunbar described process improvements, including a new four-level certificate hierarchy and plans to disclose new subordinates within seven days.
- Fastly representative — Wayne Thayer agreed with the disposition of the next update when the Basic Secure Email CA is revoked or when new information is available.
- Trustcorsystems representative — Neil Dunbar stated the Basic Secure Email CA certificate was revoked as of April 1, 2020 17:05:00 UTC and that new CRLs and OCSP responses were published.
- Fastly representative — Wayne Thayer said it appeared all questions were answered and remediation was complete.