← DigiCert cases
Bugzilla #1896053 · Delayed Revocation
Digicert: Delayed Revocation for bug 1894560
DigiCert · CLOSED
AI Summary
DigiCert faced a significant incident involving the delayed revocation of over 10,000 certificates due to incorrect business category assignments. Initially, DigiCert believed that certain circumstances allowed for delayed revocation, citing critical infrastructure and legal restrictions. However, following extensive discussions, it was clarified that there are no acceptable reasons for delayed revocation under Mozilla's policies. DigiCert has since committed to adhering strictly to the Baseline Requirements and has implemented measures to prevent future occurrences.
Chronology
- Final data on problematic certificates collected.
- Revocation of 7138 certificates completed.
- DigiCert acknowledged that delayed revocation is not acceptable.
- DigiCert committed to not delaying revocation in the future.
- Closure summary posted, confirming all action items completed.
Participants
Jeremy Rowley
Tim Callan
Rob Stradling
Zacharias Bjorngren
External References
Similar Local Cases
DigiCert: Delayed revocation of 1910322
DigiCert: Delay of revocation for EV audit inconsistency incident
DigiCert: Delayed revocation of IV certificates