← certSIGN cases
Bugzilla #1886626 Delayed Revocation

certSIGN: Delayed response to CPR

RESOLVED FIXED certSIGN
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

certSIGN reported a delayed response to a Certificate Problem Report (CPR). The CA stated it failed to receive an email containing the CPR because the message was marked as junk by its Office 365 email filter, so it did not respond within the required timeframe. certSIGN later received the same CPR from a different sender address that was not marked as junk, acknowledged it, and began investigating. After acknowledging the CPR, certSIGN revoked the non-conformant certificate within the maximum period of 5 days. The CA also documented lessons learned and corrective actions, including checking the junk and spam folders as part of routine email checks and training responsible staff on the problem reporting mechanism. The bug was marked RESOLVED with resolution FIXED, and certSIGN stated there were no additional actions unless further questions arose.

Model: gpt-5.4-nano Generated: 2026-06-13 21:29 UTC Revised: 2026-06-16 18:23 UTC Confidence: 0.86 6 comments
Chronology
  1. An email containing a CPR was received but was marked as junk by Office 365, delaying certSIGN’s response.
  2. The same CPR was received from a different sender not marked as junk, prompting investigation and acknowledgment.
  3. certSIGN informed WebTrust auditors about the incident and registered the incident report in Bugzilla.
  4. certSIGN stated it revoked the non-conformant certificate within 5 days after acknowledging the CPR.
  5. certSIGN reported internal review and added daily junk/spam folder checks to routine email checking, closing action items.
Thread Activity
  1. certSIGN — Opened the incident report, stating the CPR email was missed because it was marked as junk and that the due-time acknowledgment did not occur.
  2. certSIGN — Reported that the non-conformant certificate was revoked within 5 days of acknowledging the CPR.
  3. certSIGN — Described an internal meeting and stated the main corrective action was daily checks of junk/spam folders, with action items closed.
  4. certSIGN — Stated there were no additional actions and the bug could be considered resolved unless further questions arose.
  5. certSIGN — Reiterated there were no additional actions and the bug could be considered resolved unless further questions arose.
  6. Mozilla representative — Indicated the case could be closed May 20–24 if questions about the junk email filter/folder were answered in Bugzilla Bug #1886627.
Participants
certSIGN Mozilla representative
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#1886627 RESOLVED Delayed Revocation Opened 2024-03-20 · Closed 2024-06-01 · 99% similar
certSIGN: Delayed revocation
#1927675 RESOLVED Delayed Revocation Opened 2024-10-29 · Closed 2024-12-02 · 71% similar
iTrusChina: CPR was not responded to within 24 hours
#1826363 RESOLVED Delayed Revocation Opened 2023-04-04 · Closed 2023-06-08 · 70% similar
Asseco DS / Certum: Delayed revocation of SSL.COM cross certificate
#1656487 RESOLVED Delayed Revocation Opened 2020-07-31 · Closed 2023-02-22 · 70% similar
Izenpe: Failure to revoke within 5 days
#1886788 RESOLVED Delayed Revocation Opened 2024-03-21 · Closed 2024-06-01 · 70% similar
ACCV: Delayed revocation of TLS certificates affected by bug #1884532
#1902868 RESOLVED Delayed Revocation Opened 2024-06-15 · Closed 2024-08-21 · 70% similar
GoDaddy: CPR was not responded to in 24 hours
#1798812 RESOLVED Delayed Revocation Opened 2022-11-02 · Closed 2023-05-04 · 70% similar
CFCA: Delayed reporting of revocation of an intermediate CA certificate
#1640310 RESOLVED Delayed Revocation Opened 2020-05-22 · Closed 2023-02-22 · 69% similar
GoDaddy: Failure to revoke certificate with compromised key within 24 hours

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action