IdenTrust: Failure to Revoke Subscriber Certificates Within 5 days
This case concerns IdenTrust’s failure to revoke certain subscriber certificates within the 5-day timeframe required by the Baseline Requirements. IdenTrust stated that between 9/27/2021 and 10/2/2021, while coordinating and formulating a remediation plan for bug 1734917, it determined that revoking the certificates identified in that bug within 5 days would have had significant impact on a customer’s production services. IdenTrust also stated that, in its Risk Management review, the identified certificates posed very low security risk because the information in the certificates had been validated, and it therefore did not revoke within 5 days as required by B.R. 2. IdenTrust said the process failed to include filing a separate incident report when the expected revocation within 24 hours or five days did not take place due to a remediation plan of another separate incident. In response, Mozilla asked for additional analysis and remediation actions to prevent future revocation delays, including addressing subscriber and mitigation issues. IdenTrust reported updating its process to include filing a separate Incident Report and updating subscriber agreements to explicitly address prompt revocation, with the updated agreements in place by 12/30/2021; IdenTrust then stated it considered the remediations completed and the issue resolved, and Mozilla closed the bug on 12-Jan-2022.
- IdenTrust began coordinating and formulating a remediation plan for bug 1734917 and assessed revocation timing impact.
- IdenTrust’s assessment period concluded regarding whether revocation within 5 days would significantly impact production services.
- IdenTrust was reminded that revocation beyond 5 days requires a separate incident report (per bug 1734917 comment #2).
- IdenTrust reported updated subscriber agreements for TLS certificates were in place and considered remediations completed.
- Mozilla closed the bug after confirming closure timing.
- IdenTrust Services, LLC — IdenTrust explained it did not revoke mis-issued certificates within 5 days due to significant customer production impact and low security risk assessment, and described process updates including filing a separate incident report.
- Mm representative — A reviewer said the response did not meet expectations in Mozilla’s incident response guidance and requested analysis and remediation actions to prevent future revocation delays.
- IdenTrust Services, LLC — IdenTrust stated the factors preventing timely revocation were critical-infrastructure reliance and subscribers’ inability to replace certificates within allowed timelines, and said it would collaborate with subscribers to automate replacement.
- Mozilla representative — Mozilla asked additional questions about why critical infrastructure relied on publicly trusted certificates and what mitigation measures would prevent disruption, and requested contractual changes and timelines for meeting BR revocation requirements.
- IdenTrust Services, LLC — IdenTrust said it was updating subscriber agreements to explicitly address prompt revocation and expected completion by December 31, 2021.
- IdenTrust Services, LLC — IdenTrust reported it was on track updating the subscriber agreement with expected implementation by December 31, 2021.
- IdenTrust Services, LLC — IdenTrust stated updated subscriber agreements for TLS certificates were in place and it considered the remediations completed.
- IdenTrust Services, LLC — IdenTrust said it considered the issue resolved.
- Mozilla representative — Mozilla stated it would close the bug on 12-Jan-2022.