KIR S.A.: Certificates issued with validity period 1 second longer than stated in CPS
KIR S.A. reported that it issued certificates whose validity period was 1 second longer than the validity period stated in its Certification Practice Statement (CPS) section 6.3.2. The issue was triggered by KIR’s CPS v1.12 update published on 2020-09-01, where KIR failed to consider the RFC 5280 inclusive validity period definition (from notBefore through notAfter, inclusive). KIR stated that while the issued certificates’ validity periods were compliant with the BR, the CPS description was imprecise because it did not include the inclusive requirement. KIR said it stopped issuing certificates with the problem and identified about 300 affected certificates issued between 2020-09-17 and 2021-04-28. KIR also stated it replaced the affected certificates ASAP, noting that about 50 would be replaced within two weeks and the remaining 261 would be replaced sooner than 7 months, with some client actions needed due to use in closed banking systems. Mozilla indicated that this bug could be closed and that further tracking, if needed, could be done under other Bugzilla IDs related to delayed revocation and CPS noncompliance. The bug is resolved as FIXED.
- KIR updated its BR/CPS materials, and KIR later stated it failed to consider the RFC 5280 inclusive validity period definition.
- KIR’s CPS review period ended and KIR identified certificates issued with the 1-second-longer validity period up to this date.
- KIR filed the incident report describing certificates issued with validity periods 1 second longer than stated in its CPS.
- Mozilla scheduled closure of the bug, with potential follow-up tracking under other Bugzilla IDs.
- Kir representative — KIR described the issue: certificates had validity periods 1 second longer than stated in CPS, explained the RFC 5280 inclusive validity period cause, listed affected issuance dates and an estimated count (~300), and stated it stopped issuing the problematic certificates and began replacements ASAP.
- Kir representative — KIR clarified that it did not issue certificates greater than 398 days, but rather 1 year plus 1 second.
- Community commenter — Ryan Sleevi criticized the incident report as not meeting incident-report requirements and asked for more complete root-cause and remediation details.
- Jesperkristensen representative — Jesper Kristensen asked about whether CPS precision should be assumed similarly to BR precision, noting difficulty finding the older CPS version.
- Kir representative — KIR provided a link to an archived CPS PDF referenced in response to the CPS-precision question.
- Kir representative — KIR responded to the incident-report critique, described replacement timing constraints (closed banking systems), and reiterated replacement plans for affected certificates.
- Mozilla representative — Mozilla stated the bug could be closed and that further tracking could be done under Bugzilla #1709872 or #1705904, scheduling closure for 11-June-2021.