Buypass delayed revocation of TLS certificates after external DNS resolver incident
Buypass reported that it had issued TLS certificates using an external DNS resolver, as described in Bugzilla bug 1872371, and that affected certificates were not revoked within the required timeframe. Buypass initially described the issue as a preliminary incident report and later filed a full report explaining that revocation was delayed because the incident was discovered shortly before the Christmas holidays and because the CA needed to adjust its system to handle large renewal volumes. The report states that Buypass stopped issuance, switched Buypass ACME to an internal DNS resolver, notified subscribers, and began revoking affected certificates in batches. Buypass later said all affected certificates had been revoked or expired, and it tracked action items including subscriber communication and adding ACME Renewal Information (ARI) support. In February 2025, Buypass filed a closure summary stating that all disclosed action items were completed and requesting closure, and Mozilla indicated it would close the bug shortly thereafter.
- Buypass became aware that external DNS resolvers were considered DTP and not allowed for domain validation.
- Buypass began revoking affected certificates after delaying revocation beyond the required timeframe.
- Buypass stated that all affected certificates had been revoked or had expired.
- Buypass reported that support for ACME Renewal Information (ARI) in Buypass ACME had been implemented.
- Buypass filed a closure summary stating that all disclosed action items were completed and requesting closure.
- Buypass — Buypass opened a preliminary incident report saying affected certificates should have been revoked within 5 days after the incident was known, but revocation had not been completed.
- Namepros representative — Paul noted that the Baseline Requirements required revocation within 24 hours, not 5 days.
- Buypass — Buypass filed the full incident report, described the timeline and root cause, and said it would revoke all certificates no later than January 12, 2024.
- Buypass — Buypass corrected the incident report and said 657 certificates had already been revoked before or within 24 hours of the incident, and that 86,484 affected certificates had been revoked.
- Buypass — Buypass posted action-item updates, including ARI support due 2024-04-01 and subscriber awareness work due 2024-02-15.
- Mozilla representative — Mozilla said it was leaving the bug open for the time being.
- Buypass — Buypass posted a closure summary stating that the incident response and all disclosed action items were complete.
- Buypass — Buypass replied that its subscriber agreement already included the right to immediate revocation and that it had clarified this as an obligation in incident cases.
- Mozilla representative — Mozilla said it would close the bug on 2025-02-14.