Amazon Trust Services: Revocation Time for Intermediate Certificates
This case involves Amazon Trust Services (ATS) and the revocation of two intermediate certificates that were not revoked in a timely manner. ATS discovered that these certificates, issued in 2015, were not included in their audit reports and were only revoked on June 23, 2021, after determining that they did not meet Mozilla's policy requirements. The delay in revocation was attributed to internal evaluations and the need for a safe revocation process during the COVID-19 pandemic. The CA has since implemented policy changes to prevent similar issues in the future, including a two-person control on policy interpretation and a commitment to revoke any unused certificates created during manual ceremonies.
- ATS revokes two intermediate certificates.
- DigiCert — ATS reports the discovery of two certificates that were not revoked in 2015 and outlines the timeline of actions taken.
- Community commenter — Questions the delay between decision-making and actual revocation.
- DigiCert — Explains the reasons for the delays in reporting and revocation.
- DigiCert — ATS emphasizes the seriousness of the issue and outlines policy changes to prevent future occurrences.
- DigiCert — Requests to resolve the bug as fixed.