← SSL.com cases
Bugzilla #1752636 Delayed Revocation

SSL.com: Delayed revocation of 53 certificates affected by bug #1750631

RESOLVED FIXED SSL.com
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

SSL.com reported an incident involving delayed revocation of 53 TLS certificates that were intended to be included in a bulk revocation associated with bug #1750631. The issue was discovered when SSL.com checked revocation actions for bug #1750631, and a follow-up check found that 53 active certificates were not revoked due to a failure of the bulk revocation script. SSL.com stated that it completed revocation of the remaining 53 certificates after discovery, and a subsequent check confirmed revocation of all affected active certificates. SSL.com later reported that the underlying cause was different formatting used by RA and CA software components when storing certificate serial numbers, which affected the sub-population of certificates with serial numbers starting with one or more zeros. SSL.com said it planned remediation by adding an independent, automated verification step to the bulk revocation procedure and specifying modalities for execution and verification. Updates in the thread report drafting a revised bulk revocation procedure, testing and review of verification scripts and execution tools, end-to-end testing, and finalization of the documented procedure and tools. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:01 UTC Revised: 2026-06-16 18:43 UTC Confidence: 0.90 7 comments
Chronology
  1. SSL.com detected a potential security event and registered it internally for issuance of 4 TLS certificates based on validation methods prohibited by SC-45.
  2. SSL.com revoked 2 affected active certificates.
  3. SSL.com completed its internal investigation confirming 657 certificates were affected and planned revocation for a target population of active certificates.
  4. SSL.com initiated and then completed bulk revocation of the target population as planned.
  5. SSL.com discovered that 53 active certificates were not revoked due to a bulk revocation script failure.
  6. SSL.com completed revocation of the remaining 53 certificates and confirmed all affected active certificates were revoked.
  7. SSL.com filed a final Bugzilla report for the incident.
  8. SSL.com completed end-to-end testing and finalized the documented bulk revocation procedure and tools.
Thread Activity
  1. SSL.com — Filed the initial incident report stating the issue was discovered while checking revocation actions for bug #1750631 and describing the timeline, including that 53 active certificates were not revoked due to a bulk revocation script failure.
  2. SSL.com — Provided an update attributing the issue to different RA/CA serial-number formatting and stated a plan to add independent automated verification to the bulk revocation procedure.
  3. SSL.com — Submitted a final report stating the investigation was completed and reiterating the incident timeline and remediation direction.
  4. SSL.com — Reported drafting an updated Bulk Revocation Procedure with an independent automated verification step and progress toward testing and compliance review of the supporting tools.
  5. SSL.com — Reported testing/review of execution tools and updating documentation, with an intention to update the bug next week.
  6. SSL.com — Reported completion of tool testing for execution and updated documentation, with next step end-to-end testing before sign-off.
  7. SSL.com — Reported successful completion of end-to-end testing and review, and that the documented Bulk Revocation Procedure and relevant tools were finalized, concluding remediation actions.
Participants
SSL.com
Related Bugzilla IDs Mentioned
Similar Local Cases
#1800753 RESOLVED Delayed Revocation Opened 2022-11-15 · Closed 2023-07-21 · 86% similar
SSL.com: Delayed revocation of certificate with weak key
#1826363 RESOLVED Delayed Revocation Opened 2023-04-04 · Closed 2023-06-08 · 81% similar
Asseco DS / Certum: Delayed revocation of SSL.COM cross certificate
#1910237 RESOLVED Delayed Revocation Closure Request Opened 2024-07-27 · Closed 2025-05-13 · 62% similar
Entrust: Delayed Revocation for S/MIME certificates
#1886110 RESOLVED Delayed Revocation Opened 2024-03-19 · Closed 2025-02-14 · 62% similar
TWCA: Revocation delay for TLS certificates with non-critical basicConstraints
#1891331 RESOLVED Delayed Revocation Opened 2024-04-13 · Closed 2025-03-10 · 62% similar
NETLOCK: Policy Qualifiers other than id-qt-cps is included in TLS certificates - delayed revocation
#1656487 RESOLVED Delayed Revocation Opened 2020-07-31 · Closed 2023-02-22 · 62% similar
Izenpe: Failure to revoke within 5 days
#1634795 RESOLVED Revocation Issue Delayed Revocation Opened 2020-05-01 · Closed 2023-02-22 · 62% similar
Google Trust Services: Incorrect revocation data temporarily served for GTS Y3 & Y4
#1599788 RESOLVED Delayed Revocation Opened 2019-11-27 · Closed 2023-02-22 · 62% similar
GlobalSign: Failure to revoke noncompliant ICA within 7 days

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action