← Amazon Trust Services cases
Bugzilla #1743943 Delayed Revocation Incident

Amazon Trust Services delayed revocation of a subordinate CA and later revoked both intermediates

RESOLVED FIXED Amazon Trust Services
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns Amazon Trust Services’ delayed revocation of a subordinate CA certificate after Amazon determined the certificate had been issued in violation of its CPS and required revocation. Amazon said revoking the 2040 intermediate within the original timeframe would have caused widespread disruption because many active certificates chained to it, so it paused revocation while it investigated customer impact and alternative remediation. Mozilla and Chrome participants questioned the delay and asked for more detail on the remediation plan and how Amazon would meet BR revocation timelines in future incidents. Amazon then described a multi-ICA migration plan, including new issuing intermediates, proactive certificate replacement, and changes to AWS Certificate Manager to improve PKI agility. On 2023-05-24, Amazon reported that it revoked both referenced intermediates and asked for the issue to be closed as resolved.

Model: gpt-5.4-mini Generated: 2026-06-13 15:28 UTC Revised: 2026-06-16 18:05 UTC Confidence: 0.98 60 comments
Chronology
  1. Amazon Trust Services determined a subordinate CA certificate had been issued in violation of its CPS and required revocation.
  2. Amazon said revoking the 2040 intermediate would have implicitly revoked more than 24 million active certificates.
  3. Amazon began issuing new certificates from two new ICAs and started migrating customers.
  4. Amazon revoked the two referenced intermediate certificates.
Thread Activity
  1. DigiCert — Amazon opened the bug and explained that revoking the subordinate within seven days would have caused major customer impact, so it planned to transfer issuance and investigate retirement options.
  2. Google representative — Google said the issuance and prolonged failure to revoke violated Amazon’s policy and the Baseline Requirements, and said it would monitor the remediation.
  3. DigiCert — Amazon said it would rotate customers to a new intermediate key pair and revoke the 2040 intermediate after the 2025 intermediate expired, with migration beginning in 2023.
  4. DigiCert — Amazon said it would introduce several intermediates rather than rotate everyone to a single intermediate, and described prior operational improvements.
  5. DigiCert — Amazon said it would revoke both intermediates on 2023-05-31 and begin issuing new certificates from two new ICAs on 2022-10-11.
  6. DigiCert — Amazon reported that it revoked the two referenced certificates on 2023-05-24 and requested closure of the bug.
  7. Mozilla representative — Mozilla said it would close the bug unless additional questions or issues were raised.
Participants
DigiCert Community commenter Google representative Mozilla representative
Similar Local Cases
#1719920 RESOLVED Delayed Revocation Incident Opened 2021-07-09 · Closed 2023-02-22 · 100% similar
Amazon Trust Services: Revocation Time for Intermediate Certificates
#1743935 RESOLVED Certificate Misissuance Incident Opened 2021-12-02 · Closed 2023-02-22 · 88% similar
Amazon Trust Services: Misissuance of Subordinate Per CPS
#1707229 RESOLVED Delayed Revocation Opened 2021-04-23 · Closed 2023-02-22 · 84% similar
SECOM: Delayed Revocation of non-technically constrained FUJIFILM Certificates
#1742657 RESOLVED Delayed Revocation Opened 2021-11-23 · Closed 2023-02-22 · 83% similar
GoDaddy: Failure to Revoke Subscriber Certificates within 24 hours
#1877388 RESOLVED Delayed Revocation Incident Self Reported Incident Opened 2024-01-30 · Closed 2025-03-14 · 79% similar
Telekom Security: Revocation delay for TLS certificates with basicConstraints not marked as critical
#1792111 RESOLVED Delayed Revocation Incident Opened 2022-09-22 · Closed 2023-02-22 · 78% similar
IdenTrust: Expired CRLs
#1887888 RESOLVED Delayed Revocation Opened 2024-03-26 · Closed 2025-02-28 · 78% similar
Hongkong Post: Delayed revocation of TLS certificates with basicConstraints not marked as critical
#1718554 RESOLVED Delayed Revocation Opened 2021-06-28 · Closed 2023-02-22 · 78% similar
Actalis: Delayed revocation of non-BR-compliant CA Certificate within 7 days

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action