← HARICA cases
Bugzilla #1651465 Delayed Revocation

HARICA: Delayed revocation for non-BR-compliant CA Certificates within 7 days

RESOLVED FIXED HARICA
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns HARICA’s delayed revocation of non-TLS CA certificates that were expected to be revoked within 7 days under section 4.9.1.2 of the CA/B Forum Baseline Requirements. HARICA opened the bug to provide more specific information about challenges to replace the affected non-TLS certificates within the timeframe designed for TLS certificates. HARICA stated that it decided to violate the revocation timelines for the first time to balance ecosystem damage from mass revocation, citing that private keys of affected end-entity certificates were stored in FIPS hardware crypto-devices, making replacement more difficult and time consuming than for TLS certificates. HARICA set a deadline for automatic revocation of unexpired/unrevoked non-TLS certificates from the affected subCAs for November 2, 2020, and described plans to improve future revocation timeliness, including communicating to non-TLS subscribers to avoid “pinning” to specific issuing CAs. The thread includes discussion and feedback from Mozilla (b**********n@mozilla.com) approving the plan to proceed. HARICA later reported that a draft document with recommended practices was made public, translated, and distributed to subscribers before the end of November, and that subscribers were notified on November 30, 2020. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:11 UTC Revised: 2026-06-16 19:12 UTC Confidence: 0.90 10 comments
Chronology
  1. HARICA opened a CA Program bug describing delayed revocation for non-TLS CA certificates expected to be revoked within 7 days under the Baseline Requirements.
  2. HARICA documented its decision and rationale for delaying non-TLS revocation and set a planned automatic revocation deadline of November 2, 2020.
  3. HARICA published a draft remediation document for community feedback and planned to finalize it by October 28.
  4. HARICA reported the document was approved, being translated, and would be distributed to subscribers before the end of November.
  5. HARICA notified subscribers with recommended practices for using publicly trusted digital certificates.
Thread Activity
  1. HARICA — HARICA explained that affected CA certificates should have been revoked within 7 days per the Baseline Requirements and opened the bug to describe challenges replacing the affected non-TLS certificates.
  2. HARICA — HARICA said it had prepared most of its report on reasons for delaying revocation and expected to have it ready by July 27.
  3. HARICA — HARICA provided a decision and rationale for delaying revocation, including a planned automatic revocation deadline of November 2, 2020, and steps to prevent future revocation delays.
  4. Mozilla representative — Mozilla feedback stated the plan appeared well-considered and asked HARICA to proceed, noting they would communicate any requested modifications.
  5. HARICA — HARICA said it would keep the incident and prevention updates separate, and requested a next update date of October 5, 2020.
  6. HARICA — HARICA reported collecting subscriber feedback about services relying on subjectDN information and “pinning” practices, and said it would draft an article for subscribers.
  7. HARICA — HARICA said the draft document was completed, would be made public for community feedback, and provided a Google Docs link.
  8. HARICA — HARICA reported the document was approved, being translated, and would be distributed to subscribers before the end of November.
  9. HARICA — HARICA stated subscribers were notified with recommended practices as discussed in the main ticket.
  10. Mozilla representative — Mozilla said they intended to close the bug the week of Dec. 7–11.
Participants
HARICA Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1896553 RESOLVED Delayed Revocation Opened 2024-05-14 · Closed 2025-02-12 · 77% similar
Telia: Delayed revocation of seven (7) certificates related to incident 1896108
#1886110 RESOLVED Delayed Revocation Opened 2024-03-19 · Closed 2025-02-14 · 77% similar
TWCA: Revocation delay for TLS certificates with non-critical basicConstraints
#1945389 RESOLVED Delayed Revocation Opened 2025-02-02 · Closed 2025-05-01 · 77% similar
HARICA: delayed revocation for bug 1943596
#1887705 RESOLVED Delayed Revocation Opened 2024-03-25 · Closed 2024-09-12 · 76% similar
Entrust: Delayed revocation of clientAuth TLS Certificates without serverAuth EKU
#1891331 RESOLVED Delayed Revocation Opened 2024-04-13 · Closed 2025-03-10 · 75% similar
NETLOCK: Policy Qualifiers other than id-qt-cps is included in TLS certificates - delayed revocation
#1851710 RESOLVED Delayed Revocation Opened 2023-09-05 · Closed 2024-01-04 · 74% similar
IdenTrust: Delay beyond 5 days in revoking misissued certificates
#1905509 RESOLVED Delayed Revocation Opened 2024-06-29 · Closed 2025-05-08 · 74% similar
NETLOCK: CPR was not responded to in 24 hours
#1943596 RESOLVED Certificate Misissuance Delayed Revocation Opened 2025-01-24 · Closed 2025-05-01 · 74% similar
HARICA: S/MIME certificate issuance with incorrect commonName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action