SSL.com: Delayed revocation of 53 certificates affected by bug #1750631
SSL.com reported an incident involving delayed revocation of 53 TLS certificates that were intended to be included in a bulk revocation associated with bug #1750631. The issue was discovered when SSL.com checked revocation actions for bug #1750631, and a follow-up check found that 53 active certificates were not revoked due to a failure of the bulk revocation script. SSL.com stated that it completed revocation of the remaining 53 certificates after discovery, and a subsequent check confirmed revocation of all affected active certificates. SSL.com later reported that the underlying cause was different formatting used by RA and CA software components when storing certificate serial numbers, which affected the sub-population of certificates with serial numbers starting with one or more zeros. SSL.com said it planned remediation by adding an independent, automated verification step to the bulk revocation procedure and specifying modalities for execution and verification. Updates in the thread report drafting a revised bulk revocation procedure, testing and review of verification scripts and execution tools, end-to-end testing, and finalization of the documented procedure and tools. The bug is marked RESOLVED with resolution FIXED.
- SSL.com detected a potential security event and registered it internally for issuance of 4 TLS certificates based on validation methods prohibited by SC-45.
- SSL.com revoked 2 affected active certificates.
- SSL.com completed its internal investigation confirming 657 certificates were affected and planned revocation for a target population of active certificates.
- SSL.com initiated and then completed bulk revocation of the target population as planned.
- SSL.com discovered that 53 active certificates were not revoked due to a bulk revocation script failure.
- SSL.com completed revocation of the remaining 53 certificates and confirmed all affected active certificates were revoked.
- SSL.com filed a final Bugzilla report for the incident.
- SSL.com completed end-to-end testing and finalized the documented bulk revocation procedure and tools.
- SSL.com — Filed the initial incident report stating the issue was discovered while checking revocation actions for bug #1750631 and describing the timeline, including that 53 active certificates were not revoked due to a bulk revocation script failure.
- SSL.com — Provided an update attributing the issue to different RA/CA serial-number formatting and stated a plan to add independent automated verification to the bulk revocation procedure.
- SSL.com — Submitted a final report stating the investigation was completed and reiterating the incident timeline and remediation direction.
- SSL.com — Reported drafting an updated Bulk Revocation Procedure with an independent automated verification step and progress toward testing and compliance review of the supporting tools.
- SSL.com — Reported testing/review of execution tools and updating documentation, with an intention to update the bug next week.
- SSL.com — Reported completion of tool testing for execution and updated documentation, with next step end-to-end testing before sign-off.
- SSL.com — Reported successful completion of end-to-end testing and review, and that the documented Bulk Revocation Procedure and relevant tools were finalized, concluding remediation actions.