← SSL.com cases
Bugzilla #1800753 Delayed Revocation

SSL.com: Delayed revocation of certificate with weak key

RESOLVED WONTFIX SSL.com
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns SSL.com's delayed revocation of a certificate containing keys vulnerable to Fermat factorization. The certificate was revoked 25 hours and 50 minutes after SSL.com was made aware of the vulnerability, which is outside the required 24-hour revocation timeframe for such issues as per the Baseline Requirements. SSL.com acknowledged the delay and explained that they needed to analyze the situation before proceeding with revocation. They also indicated that the current guidelines lack clarity on what constitutes a 'demonstrated or proven method' for key compromise. The case has been resolved with SSL.com committing to improve their processes and monitoring for similar vulnerabilities in the future.

Model: gpt-4o-mini Generated: 2026-06-13 21:01 UTC Revised: 2026-06-16 18:46 UTC Confidence: 0.85 18 comments
Chronology
  1. Certificate with weak key was revoked.
Thread Activity
  1. Thisisntrocket representative — Reported the delayed revocation of a certificate with weak key.
  2. SSL.com — Acknowledged receipt of the bug report and planned to respond.
  3. SSL.com — Explained the rationale for the delayed revocation and outlined steps taken to address the issue.
  4. Mozilla representative — Indicated that the underlying issues have been adequately addressed.
  5. Mozilla representative — Closed the bug as the issues are being addressed by the CA/Browser Forum.
Participants
Thisisntrocket representative SSL.com Mozilla representative
External References
Similar Local Cases
#1752636 RESOLVED Delayed Revocation Opened 2022-01-28 · Closed 2023-02-22 · 86% similar
SSL.com: Delayed revocation of 53 certificates affected by bug #1750631
#1826363 RESOLVED Delayed Revocation Opened 2023-04-04 · Closed 2023-06-08 · 86% similar
Asseco DS / Certum: Delayed revocation of SSL.COM cross certificate
#1851710 RESOLVED Delayed Revocation Opened 2023-09-05 · Closed 2024-01-04 · 75% similar
IdenTrust: Delay beyond 5 days in revoking misissued certificates
#1698936 RESOLVED Delayed Revocation Opened 2021-03-16 · Closed 2023-02-22 · 75% similar
Sectigo: ZeroSSL: failure to revoke within 24 hours
#1651637 RESOLVED Delayed Revocation Opened 2020-07-09 · Closed 2023-02-22 · 75% similar
Firmaprofesional: Failure to revoke ICAs within 7 days: OCSP EKU
#1692535 RESOLVED Delayed Revocation Opened 2021-02-12 · Closed 2023-02-22 · 73% similar
Camerfirma: Delayed revocations of certificates issued by old CAs with an RSA modulus size of 2047 bits
#1639794 RESOLVED Delayed Revocation Opened 2020-05-21 · Closed 2023-02-22 · 71% similar
Let's Encrypt: Failure to revoke key-compromised certificate within 24 hours
#1639801 RESOLVED Delayed Revocation Opened 2020-05-21 · Closed 2023-02-22 · 70% similar
DigiCert: Failure to revoke key-compromised certificates within 24 hours

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action