Telia: Two Intermediate CA certificates not listed in audit report
This case concerns Telia reporting that two intermediate CA (ICA) certificates were missing from audit listings in the CCADB ALV process. Telia said it learned of the issue via the January 2020 CA communication requirements and analyzed why the certificates were not included in the auditors’ list. Telia’s analysis attributed the omission to the certificates not being present in the Telia CA online system used by auditors, including one certificate that was not migrated from an abolished offline CA system and another that was not installed to the online system due to an invalid Subject value. Telia reported the issue to the CCADB system and asked how to resolve the “Intermediate Certs with Failed ALV Results” status, and Mozilla confirmed that revocation was the right solution and that an incident report was required. Telia then performed an incident report and revoked the certificates in its offline Root CA system, updating its Root CRL to include them. A Mozilla participant later confirmed that the two CA certificates were revoked and that the remaining questions were answered. The bug is resolved as FIXED.
- Telia received the January 2020 CA communication message referencing CCADB ALV requirements.
- Telia analyzed that the two listed CA certificates were not active and scheduled deeper analysis.
- Telia completed detailed analysis explaining why the two certificates were missing from audit listings.
- Telia reported the issue to the CCADB system and provided a detailed explanation in the January 2020 communication report.
- Mozilla confirmed revocation was the correct solution and that an incident report was required.
- Telia filed the incident report in Bugzilla.
- Telia revoked the certificates in its offline Root CA system and updated its Root CRL to include them.
- A Mozilla participant confirmed the certificates were revoked and that questions were answered.
- Teliasonera representative — Telia described how it became aware of the missing audit listings, provided a timeline, identified the two ICA certificates, and stated the resolution steps taken.
- Teliasonera representative — Telia stated it revoked the certificates in its offline Root CA system, updated its Root CRL, and said the CCADB ALV issue should be solved.
- Fastly representative — Fastly confirmed the two CA certificates are revoked and that all questions have been answered.