Apple: Revocation Delay for TLS certificates issued outside the TTL of the CAA record
Apple Public CA reported a compliance incident regarding the delayed revocation of TLS certificates that were issued outside the Time-To-Live (TTL) of the Certificate Authority Authorization (CAA) record. The issue was identified on June 29, 2023, when it was discovered that the requirements of BR section 3.2.2.8 were not met, leading to a delay in revocation beyond the stipulated timeframe. The CA took corrective action within 24 hours and began the process of replacing and revoking the affected certificates. As of September 13, 2023, all 1,717 affected certificates had been accounted for, with no valid certificates remaining. The case has been resolved with the CA actively working to ensure compliance moving forward.
- Compliance incident identified regarding TLS certificates issued outside the TTL of the CAA record.
- All affected certificates accounted for, with no valid certificates remaining.
- Apple representative — Reported compliance incident and outlined the steps taken to address the issue.
- Mozilla representative — Inquired if there were any further questions or comments before closing the case.