SwissSign: EV delayed revocation
This case reports a delayed revocation incident involving SwissSign EV certificates. SwissSign states the delayed revocation was requested by customers for certain mis-issued certificates that were reported in Bugzilla 1860750, and that the delay went beyond the 5-day period mandated by CA/B Baseline Requirements 4.9.1.1. SwissSign explains it decided to delay revocation for 40 EV certificates after weighing factors including that the mis-issuance was compliance-related with no security impact, that affected customers were part of critical infrastructure, and that some customers used certificate pinning in mobile apps. SwissSign posted an incident report with a timeline and root-cause analysis, and listed action items including revoking remaining mis-issued certificates by the given deadlines and providing weekly updates. SwissSign later reported revocation progress: it said 33 certificates scheduled for revocation by 03.11.2023 23:59 were revoked, then the remaining certificates scheduled for 10.11.2023 23:59 and 17.11.2023 23:59 were revoked. SwissSign stated that with this, all certificates affected by Bugzilla 1860750 were revoked and requested closure; the bug was resolved as FIXED.
- A compliance incident was raised that led to Bugzilla 1860750.
- SwissSign posted this delayed-revocation incident report after collecting customer requests and performing risk analysis.
- SwissSign reported that 33 certificates scheduled for revocation by 03.11.2023 23:59 were revoked.
- SwissSign reported that 3 certificates scheduled for revocation by 10.11.2023 23:59 were revoked.
- SwissSign reported that 4 certificates scheduled for revocation by 17.11.2023 23:59 were revoked, completing revocation of all certificates affected by Bugzilla 1860750.
- SwissSign AG — Created the incident report attachment and described why SwissSign delayed revocation beyond the mandated 5 days for 40 EV certificates.
- Google representative — Requested updates to the report’s Impact, Timeline, Lessons Learned/Action Items, and asked whether other options were explored to avoid future delayed revocations.
- SwissSign AG — Provided updated sections (Impact, Timeline, Root Cause, and Action Items) and responded to the questions about possible additional actions.
- SwissSign AG — Updated that the 33 certificates scheduled to be revoked by 03.11.2023 23:59 latest have been revoked.
- Google representative — Asked whether other approaches or solutions were considered to address contributing factors related to subscribers’ emergency processes and regulatory requirements.
- SwissSign AG — Responded that SwissSign is considering communicating learnings to its userbase and restated its view that it prioritized revocation within required timeframes.
- SwissSign AG — Updated that the 3 certificates scheduled to be revoked by 10.11.2023 23:59 latest have been revoked.
- SwissSign AG — Updated that the 4 certificates scheduled to be revoked by 17.11.2023 23:59 latest have been revoked and requested closure.
- Mozilla representative — Indicated the bug would be closed the next day (1-Dec-2023).