← Buypass cases
Bugzilla #1628292
Certificate Problem Report
Buypass: Failure to revoke PSD2 QWACs within mandated 5 days
RESOLVED
FIXED
Buypass
AI Summary
Buypass reported a failure to revoke 16 PSD2 Qualified Website Authentication Certificates (QWACs) within the mandated 5-day period. The issue was identified on March 26, 2020, following a notification from the PSD2 community. After acknowledging the problem, Buypass implemented a fix and deployed it to production by March 29, 2020. The affected certificates were eventually revoked on April 4, 2020. Buypass has since improved its incident management processes to prevent similar issues in the future.
Chronology
- Buypass received notification of the problem.
- Fix deployed to production.
- All affected certificates were revoked.
Participants
Mads Henriksveen
Ryan Sleevi
Ben Wilson
External References
Similar Local Cases
Buypass: Illegal Business Category in a PSD2 QWAC
Buypass: PSD2 QWAC with RSA modulus not divisible by 8
Buypass: Missing NCA identifier in cabfOrganizationIdentifier in PSD2 QWACs
Buypass: intermediate certificates not revoked within BR time period
Buypass: Intermediate certificates not listed in audit reports
Buypass: Insufficient Serial Number Entropy
GoDaddy: Failure to revoke certificate with compromised key within 24 hours
Entrust: Failure to revoke a certificate