Microsec: Late response to a CPR
Microsec reported that it received an email incident report about a potentially misissued EV certificate, but did not react in time. The issue described in the problem report was that the EV certificate did not contain the CPSuri link. Microsec stated that, due to the delay, it created multiple incident reports, and this bug specifically focuses on the failure to respond to the certificate problem report in a complete and/or timely manner. Microsec provided a timeline of how the first and second emails were handled in its OTRS system and how the issue was investigated after the second email. Microsec also described remediation action items to improve its OTRS processing rules and to set up a dedicated CCADB contact email alias, including later steps such as forwarding and SMS notifications. The bug was resolved as FIXED, and Mozilla asked whether it could be closed; Microsec responded that it had no open issues regarding the incident report.
- Microsec received an initial email reporting a potentially misissued EV certificate and processed it via its OTRS system.
- Microsec received a second email about the same potentially misissued EV certificate and began investigating after prioritization.
- Microsec published an incident status report with action items to improve OTRS processing and CCADB email handling.
- Microsec reported completing testing of a new notification workflow and changing the CCADB contact email alias.
- Mozilla requested closure; Microsec stated there were no open issues.
- Microsec representative — Opened the incident report bug, stating Microsec did not respond in time to a certificate problem report and that this bug covers the late response (Bug #3), with supporting timeline and remediation action items.
- Community commenter — Commented that Bug #3 should focus on failure to respond to a certificate problem report in a timely and thorough manner.
- Community commenter — Requested immediate action to rectify issues, including issuing corrected certificates and promptly revoking misissued certificates.
- Microsec representative — Published an incident status report noting temporary forwarding of CCADB-related emails to the CTO and listing action items with due dates.
- Microsec representative — Published another status report describing creation of a CCADB contact email address and forwarding to an internal compliance mailing list, with updated action item statuses.
- Microsec representative — Reported completion of testing for a new CCADB email notification workflow, including SMS notifications, and that OTRS processing rule and dedicated email configuration action items were done.
- Mozilla representative — Asked whether there were any other comments or questions and whether the matter could be closed.
- Microsec representative — Confirmed there were no open issues regarding the incident report.
- Mozilla representative — Indicated the bug would be closed on or about Wed. 28-Aug-2024.