E-Tugra: The failure to revoke a certificate
E-Tugra reported a revocation failure for a certificate with commonName "cebimde.com.tr" that was not included in the SAN of the certificate. The CA said it received an email on 15 Jan 2021 about the revocation issue, and that revocation was completed on 18 Jan 2021, but the certificate “must be revoked in 5 days.” E-Tugra stated that the certificate was reissued and marked for revocation, but that the revocation process was not completed at that time; Security Group investigated and revoked on 18 Jan 2021 while System Developers continued investigating the root cause. The CA said its investigation found the error was caught by its post-validation controls and therefore zlint controls were not applied, and it described remediation steps including revising post-validation routines, running zlint controls for all SSL certificates regardless of post-validation results, and adding zlint before issuance. E-Tugra also described enhancing procedures so that certificate errors trigger recurring notifications until an action is taken, and rebuilding revocation workflows. Mozilla staff indicated an expectation to close the matter after changes were put into production, and the bug is marked RESOLVED with resolution FIXED.
- E-Tugra issued the certificate later involved in the revocation issue.
- E-Tugra found the certificate problem and issued a new certificate, marking the first certificate for revocation.
- E-Tugra received an external email reporting a revocation problem for the certificate.
- E-Tugra completed revocation for the reported certificate.
- E-Tugra planned to deploy updated validation and workflow controls to production.
- E-Tugra — Opened a preliminary report describing the revocation timing issue and a timeline of investigation and remediation planning.
- E-Tugra — Provided a fuller explanation of validation controls, why zlint was not applied in this case, and additional remediation steps.
- Fozzie representative — Asked for clarification on how E-Tugra concluded the issue was not misissuance given zlint citations referencing BRs.
- E-Tugra — Explained that zlint controls were skipped because the certificate failed post-validation controls, and described changes to run zlint independently and improve notifications and revocation procedures.
- Community commenter — Questioned whether remediation was sufficient and suggested pre-issuance linting rather than relying on post-issuance linting.
- E-Tugra — Stated additional pre-issuance zlinting was implemented and planned production rollout at the end of the week (3 April).
- E-Tugra — Updated that post-validation controls were reviewed, zlint validations would run independently and always, and zlint would also be added before issuance; described workflow changes for revocation review.
- Mozilla representative — Indicated an expectation to close the matter after confirming changes were put into production.