← e-commerce monitoring GmbH cases
Bugzilla #1716163
Certificate Problem Report
e-commerce monitoring GmbH: Revoked test website not using revoked certificate
RESOLVED
FIXED
e-commerce monitoring GmbH
AI Summary
The case involves e-commerce monitoring GmbH, which was reported for not using a revoked certificate on their test website. The issue was identified when the website was serving a valid certificate despite the revocation. The CA acknowledged the oversight and committed to providing a full incident report. Subsequent discussions highlighted the need for improved compliance with baseline requirements and the implementation of automated processes to prevent future occurrences. The issue has since been resolved, and the CA has taken steps to enhance their operational practices.
Chronology
- Initial report of the revoked certificate issue.
- CA acknowledged the issue and promised a full incident report.
- Full incident report submitted by the CA.
- CA requested closure of the bug as the issue was resolved.
Participants
Andrew Ayer
Daniel Zens
Matthias
Ryan Sleevi
B. Wilson
External References
Similar Local Cases
e-commerce monitoring GmbH: CN domain not in SAN
e-commerce monitoring GmbH: SCT in precertificate
e-commerce monitoring GmbH: CRLs with mismatched issuer
Entrust: Late Revocation for SSL Certificates issued with Un-verified IP Addresses
KIR S.A.: CN domain not in SAN
Google Trust Services: Forbidden Domain Validation Method 3.2.2.4.10
Entrust: Test Website Certificates Expired
Asseco DS / Certum: Failure to provide a preliminary report within 24 hours.