HARICA: Delayed revocation for non-BR-compliant CA Certificates within 7 days
This case concerns HARICA’s delayed revocation of non-TLS CA certificates that were expected to be revoked within 7 days under section 4.9.1.2 of the CA/B Forum Baseline Requirements. HARICA opened the bug to provide more specific information about challenges to replace the affected non-TLS certificates within the timeframe designed for TLS certificates. HARICA stated that it decided to violate the revocation timelines for the first time to balance ecosystem damage from mass revocation, citing that private keys of affected end-entity certificates were stored in FIPS hardware crypto-devices, making replacement more difficult and time consuming than for TLS certificates. HARICA set a deadline for automatic revocation of unexpired/unrevoked non-TLS certificates from the affected subCAs for November 2, 2020, and described plans to improve future revocation timeliness, including communicating to non-TLS subscribers to avoid “pinning” to specific issuing CAs. The thread includes discussion and feedback from Mozilla (b**********n@mozilla.com) approving the plan to proceed. HARICA later reported that a draft document with recommended practices was made public, translated, and distributed to subscribers before the end of November, and that subscribers were notified on November 30, 2020. The bug is marked RESOLVED with resolution FIXED.
- HARICA opened a CA Program bug describing delayed revocation for non-TLS CA certificates expected to be revoked within 7 days under the Baseline Requirements.
- HARICA documented its decision and rationale for delaying non-TLS revocation and set a planned automatic revocation deadline of November 2, 2020.
- HARICA published a draft remediation document for community feedback and planned to finalize it by October 28.
- HARICA reported the document was approved, being translated, and would be distributed to subscribers before the end of November.
- HARICA notified subscribers with recommended practices for using publicly trusted digital certificates.
- HARICA — HARICA explained that affected CA certificates should have been revoked within 7 days per the Baseline Requirements and opened the bug to describe challenges replacing the affected non-TLS certificates.
- HARICA — HARICA said it had prepared most of its report on reasons for delaying revocation and expected to have it ready by July 27.
- HARICA — HARICA provided a decision and rationale for delaying revocation, including a planned automatic revocation deadline of November 2, 2020, and steps to prevent future revocation delays.
- Mozilla representative — Mozilla feedback stated the plan appeared well-considered and asked HARICA to proceed, noting they would communicate any requested modifications.
- HARICA — HARICA said it would keep the incident and prevention updates separate, and requested a next update date of October 5, 2020.
- HARICA — HARICA reported collecting subscriber feedback about services relying on subjectDN information and “pinning” practices, and said it would draft an article for subscribers.
- HARICA — HARICA said the draft document was completed, would be made public for community feedback, and provided a Google Docs link.
- HARICA — HARICA reported the document was approved, being translated, and would be distributed to subscribers before the end of November.
- HARICA — HARICA stated subscribers were notified with recommended practices as discussed in the main ticket.
- Mozilla representative — Mozilla said they intended to close the bug the week of Dec. 7–11.