← certSIGN cases
Bugzilla #1886627
Delayed Revocation
certSIGN: Delayed revocation
RESOLVED
FIXED
certSIGN
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
certSIGN experienced a delayed revocation of a misissued certificate due to an email marked as junk that contained a Certificate Problem Report. The incident was triggered when certSIGN received a report about a non-conformity in the Subject Attribute Encoding order, but the initial notification was not acted upon in time. After acknowledging the issue, certSIGN revoked the certificate within the required timeframe and implemented measures to prevent future occurrences, including daily checks of the junk email folder. The case has been resolved with all action items completed.
Chronology
- certSIGN registered the incident report in Bugzilla.
Thread Activity
- certSIGN — certSIGN received an email regarding a misissued certificate but marked it as junk.
- certSIGN — The non-conformant certificate was revoked within the maximum period of 5 days.
- certSIGN — An internal meeting was held to address email handling and prevent future issues.
- certSIGN — certSIGN considers the bug resolved unless further questions arise.
Participants
certSIGN
Community commenter
Mozilla representative
External References
Similar Local Cases
certSIGN: Delayed response to CPR
D-Trust: Delay beyond 5 days in revoking misissued certificate
Telia: Delayed revocation of seven (7) certificates related to incident 1896108
GoDaddy: CPR was not responded to in 24 hours
GDCA: Delayed revocation of SSL/TLS certificates with Non-critical Basic Constraints
CFCA: Delayed revocation of TLS certificates(basicConstraints extension not marked as critical)
Buypass: TLS certificates not revoked within 5 days
Entrust: CPR was not responded to in 24 hours