Microsec: Failure to revoke noncompliant ICA within 7 days
Microsec Ltd. faced a delayed revocation issue regarding noncompliant Intermediate CA (ICA) certificates that were not revoked within the required timeframe of 7 days. The CA was notified of the misissued OCSP responder certificates on July 1, 2020, and initiated an investigation. Although two affected ICA certificates were revoked, two others could not be revoked in time due to their significant impact on users. Microsec developed a plan to address the issue, which included destroying the affected keys and issuing new certificates. By October 16, 2020, all affected keys were destroyed, and the misissued ICA certificates were revoked, resolving the incident.
- Microsec received notification about misissued OCSP responder certificates.
- Microsec destroyed all ICA keys affected in this incident.
- Microsec representative — Microsec began investigating the misissued OCSP responder certificates.
- Microsec representative — Microsec reported ongoing work on alternative solutions to the issue.
- Microsec representative — Microsec revoked the misissued ICA certificates.
- Microsec representative — Microsec confirmed the destruction of all affected ICA keys.