Microsec: ALV Failures
This case involves Microsec Ltd. addressing discrepancies identified by Mozilla's Audit Letter Validation (ALV) tool related to their CA certificates. The issues arose from the need for all subordinate CA certificates to be included in audit letters as part of compliance checks. Microsec reported multiple reissues of their root and subordinate CA certificates over the years, maintaining validity for earlier versions to ensure long-term signature validation. Following an investigation, Microsec provided a new attestation letter that resolved the ALV issues. The bug was marked as resolved after confirming that there were no remaining ALV failures in the Common CA Database (CCADB).
- Microsec Ltd. reported ALV discrepancies to Mozilla.
- Microsec received a new Attestation Letter including all versions of their root certificate.
- CCADB was updated, confirming no ALV failures.
- Fastly representative — Requested a full incident report and update on the audit report.
- Microsec representative — Informed about an open ALV issue and pending attestation letter.
- Microsec representative — Provided the incident report link as previously agreed.