Google Trust Services: Revocation data publication delay for revoked unused subordinate CAs
Google Trust Services reported that revocation information was not published within 24 hours of the revocation date specified in revocation data for several revoked unused subordinate CA certificates. The engineers who performed the revocation realized the publication timing issue after the 24-hour window elapsed. Google Trust Services investigated the problem, collected evidence, and declared an internal security event during the response. The CRLs and OCSP responses were later rolled out and became publicly available globally. The incident report described that six unused subordinate certificates were revoked with a revocation timestamp of 2023-06-13 00:00:00 UTC, and the revocation data was published on 2023-06-15 04:35. In follow-up, Google Trust Services stated it completed the actions in section 7 of the incident report, including adding a linter to verify ceremony input configuration and amending procedures and checklists to ensure timely publication. The bug is marked RESOLVED with resolution FIXED.
- Google Trust Services generated revocation data during a revocation ceremony for several unused subordinate CA certificates.
- The 24-hour window for publishing the generated revocation information elapsed without publication.
- Google Trust Services published the updated CRLs and OCSP responses globally after investigating the delay.
- Google Trust Services reported completion of incident-report actions and requested closure.
- Google representative — Google Trust Services said it identified a publication timing issue for revocation data after revoking several unused subordinate CAs and would post a full report within seven days.
- Google representative — Google Trust Services provided an incident report describing that revocation information was not published within 24 hours and included a detailed timeline of the ceremony, investigation, and publication steps.
- Google representative — Google Trust Services stated it completed all actions described in section 7 of the incident report, including adding a linter and updating procedures/checklists for timely revocation data publication.
- Mozilla representative — Mozilla indicated it would close the bug on 28-July-2023 if there were no further questions or comments.