SSL.com: Delayed revocation of certificate with weak key
This case concerns SSL.com's delayed revocation of a certificate containing keys vulnerable to Fermat factorization. The certificate was revoked 25 hours and 50 minutes after SSL.com was made aware of the vulnerability, which is outside the required 24-hour revocation timeframe for such issues as per the Baseline Requirements. SSL.com acknowledged the delay and explained that they needed to analyze the situation before proceeding with revocation. They also indicated that the current guidelines lack clarity on what constitutes a 'demonstrated or proven method' for key compromise. The case has been resolved with SSL.com committing to improve their processes and monitoring for similar vulnerabilities in the future.
- Certificate with weak key was revoked.
- Thisisntrocket representative — Reported the delayed revocation of a certificate with weak key.
- SSL.com — Acknowledged receipt of the bug report and planned to respond.
- SSL.com — Explained the rationale for the delayed revocation and outlined steps taken to address the issue.
- Mozilla representative — Indicated that the underlying issues have been adequately addressed.
- Mozilla representative — Closed the bug as the issues are being addressed by the CA/Browser Forum.