← Amazon Trust Services cases
Bugzilla #1743943 Delayed Revocation

Amazon Trust Services: Delayed Revocation of Subordinate CA

RESOLVED FIXED Amazon Trust Services
AI Summary

Amazon Trust Services faced challenges in revoking a subordinate CA certificate due to potential negative impacts on over 24 million active certificates. The CA received a report indicating a violation of their Certificate Policy Statement (CPS) and initially planned to revoke the certificate within a week. However, after assessing the situation, they determined that immediate revocation would disrupt services and opted to delay the action while exploring alternative solutions. The CA has committed to transitioning to a new intermediate certificate and has set a timeline for revocation, which was ultimately executed on May 24, 2023.

Model: gpt-4o-mini Generated: 2026-06-13 15:28 UTC Confidence: 0.90
Chronology
  1. Amazon Trust Services received a report regarding a potential CPS violation.
  2. Target date for revocation was set for December 1, 2021.
  3. Amazon Trust Services provided a timeline for action items related to the incident.
  4. Amazon Trust Services revoked the subordinate CA certificate.
Participants
Trevoli (Amazon Trust Services) Ryan Sleevi (Google) Ryan Dickson (Google Chrome)
External References
Similar Local Cases
#1652604 RESOLVED Delayed Revocation Opened 2020-07-13 · Closed 2023-02-22 · 40% similar
PKIoverheid: Failure to revoke within 7 days: OCSP EKU issue
#1752636 RESOLVED Delayed Revocation Opened 2022-01-28 · Closed 2023-02-22 · 40% similar
SSL.com: Delayed revocation of 53 certificates affected by bug #1750631
#1652610 RESOLVED Delayed Revocation Opened 2020-07-13 · Closed 2023-02-22 · 40% similar
SECOM: Delayed Revocation of CA Certificate with OCSP EKU Issue
#1692535 RESOLVED Delayed Revocation Opened 2021-02-12 · Closed 2023-02-22 · 40% similar
Camerfirma: Delayed revocations of certificates issued by old CAs with an RSA modulus size of 2047 bits
#1580525 RESOLVED Delayed Revocation Opened 2019-09-11 · Closed 2023-02-22 · 40% similar
D-TRUST: Delayed revocation of EV certificates
#1891331 RESOLVED Delayed Revocation Opened 2024-04-13 · Closed 2025-03-10 · 39% similar
NETLOCK: Policy Qualifiers other than id-qt-cps is included in TLS certificates - delayed revocation
#2034359 ASSIGNED Delayed Revocation Opened 2026-04-23 Still Open · 39% similar
SwissSign: Delayed revocation related to Bugzilla 2033000
#1651828 RESOLVED Delayed Revocation Opened 2020-07-09 · Closed 2023-02-22 · 39% similar
DigiCert: Delay of revocation for EV audit inconsistency incident

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action