← HARICA cases
Bugzilla #1651465
Delayed Revocation
HARICA: Delayed revocation for non-BR-compliant CA Certificates within 7 days
RESOLVED
FIXED
HARICA
AI Summary
HARICA faced challenges in revoking non-BR-compliant CA Certificates within the required 7-day timeframe due to the complexity of replacing certificates stored in FIPS hardware crypto-devices. The organization identified that many affected certificates were crucial for academic transactions, and the summer break in Greek universities further complicated timely replacements. HARICA set a new deadline for automatic revocation by November 2, 2020, and is implementing measures to prevent future delays.
Chronology
- Bug created to address delayed revocation.
- HARICA outlines reasons for revocation delay.
- New deadline for revocation set.
- Subscribers notified of best practices.
Participants
Dimitris Zacharopoulos
Ben Wilson
External References
Similar Local Cases
HARICA: delayed revocation for bug 1943596
Microsec: Delayed revocation of the misissued certificates
Entrust: Delayed revocation of clientAuth TLS Certificates without serverAuth EKU
Camerfirma: Delayed revocations related to Invalid authorityKeyIdentifier - recurrent incident
PKIoverheid: Failure to revoke within 7 days: OCSP EKU issue
NETLOCK: Policy Qualifiers other than id-qt-cps is included in TLS certificates - delayed revocation
e-commerce monitoring GmbH: Delayed revocation
Camerfirma: Delayed revocations of certificates issued by old CAs with an RSA modulus size of 2047 bits