Amazon Trust Services delayed revocation of a subordinate CA and later revoked both intermediates
This case concerns Amazon Trust Services’ delayed revocation of a subordinate CA certificate after Amazon determined the certificate had been issued in violation of its CPS and required revocation. Amazon said revoking the 2040 intermediate within the original timeframe would have caused widespread disruption because many active certificates chained to it, so it paused revocation while it investigated customer impact and alternative remediation. Mozilla and Chrome participants questioned the delay and asked for more detail on the remediation plan and how Amazon would meet BR revocation timelines in future incidents. Amazon then described a multi-ICA migration plan, including new issuing intermediates, proactive certificate replacement, and changes to AWS Certificate Manager to improve PKI agility. On 2023-05-24, Amazon reported that it revoked both referenced intermediates and asked for the issue to be closed as resolved.
- Amazon Trust Services determined a subordinate CA certificate had been issued in violation of its CPS and required revocation.
- Amazon said revoking the 2040 intermediate would have implicitly revoked more than 24 million active certificates.
- Amazon began issuing new certificates from two new ICAs and started migrating customers.
- Amazon revoked the two referenced intermediate certificates.
- DigiCert — Amazon opened the bug and explained that revoking the subordinate within seven days would have caused major customer impact, so it planned to transfer issuance and investigate retirement options.
- Google representative — Google said the issuance and prolonged failure to revoke violated Amazon’s policy and the Baseline Requirements, and said it would monitor the remediation.
- DigiCert — Amazon said it would rotate customers to a new intermediate key pair and revoke the 2040 intermediate after the 2025 intermediate expired, with migration beginning in 2023.
- DigiCert — Amazon said it would introduce several intermediates rather than rotate everyone to a single intermediate, and described prior operational improvements.
- DigiCert — Amazon said it would revoke both intermediates on 2023-05-31 and begin issuing new certificates from two new ICAs on 2022-10-11.
- DigiCert — Amazon reported that it revoked the two referenced certificates on 2023-05-24 and requested closure of the bug.
- Mozilla representative — Mozilla said it would close the bug unless additional questions or issues were raised.