← Microsec Ltd. cases
Bugzilla #1886998 Problem Reporting Failure

Microsec: Late response to a CPR

RESOLVED FIXED Microsec Ltd.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Microsec reported that it received an email incident report about a potentially misissued EV certificate, but did not react in time. The issue described in the problem report was that the EV certificate did not contain the CPSuri link. Microsec stated that, due to the delay, it created multiple incident reports, and this bug specifically focuses on the failure to respond to the certificate problem report in a complete and/or timely manner. Microsec provided a timeline of how the first and second emails were handled in its OTRS system and how the issue was investigated after the second email. Microsec also described remediation action items to improve its OTRS processing rules and to set up a dedicated CCADB contact email alias, including later steps such as forwarding and SMS notifications. The bug was resolved as FIXED, and Mozilla asked whether it could be closed; Microsec responded that it had no open issues regarding the incident report.

Model: gpt-5.4-nano Generated: 2026-06-13 21:15 UTC Revised: 2026-06-16 19:16 UTC Confidence: 0.84 9 comments
Chronology
  1. Microsec received an initial email reporting a potentially misissued EV certificate and processed it via its OTRS system.
  2. Microsec received a second email about the same potentially misissued EV certificate and began investigating after prioritization.
  3. Microsec published an incident status report with action items to improve OTRS processing and CCADB email handling.
  4. Microsec reported completing testing of a new notification workflow and changing the CCADB contact email alias.
  5. Mozilla requested closure; Microsec stated there were no open issues.
Thread Activity
  1. Microsec representative — Opened the incident report bug, stating Microsec did not respond in time to a certificate problem report and that this bug covers the late response (Bug #3), with supporting timeline and remediation action items.
  2. Community commenter — Commented that Bug #3 should focus on failure to respond to a certificate problem report in a timely and thorough manner.
  3. Community commenter — Requested immediate action to rectify issues, including issuing corrected certificates and promptly revoking misissued certificates.
  4. Microsec representative — Published an incident status report noting temporary forwarding of CCADB-related emails to the CTO and listing action items with due dates.
  5. Microsec representative — Published another status report describing creation of a CCADB contact email address and forwarding to an internal compliance mailing list, with updated action item statuses.
  6. Microsec representative — Reported completion of testing for a new CCADB email notification workflow, including SMS notifications, and that OTRS processing rule and dedicated email configuration action items were done.
  7. Mozilla representative — Asked whether there were any other comments or questions and whether the matter could be closed.
  8. Microsec representative — Confirmed there were no open issues regarding the incident report.
  9. Mozilla representative — Indicated the bug would be closed on or about Wed. 28-Aug-2024.
Participants
Microsec representative Community commenter Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2049237 ASSIGNED Ca Certificate Compliance Incident Externally Reported Incident Revocation Issue Opened 2026-06-22 Still Open · 66% similar
HARICA: Continued issuance and refusal to revoke TLS certificates for EU-sanctioned blocked entities (Sberbank, VTB, KAMAZ, ANO Dialog)
#1649947 RESOLVED Certificate Misissuance Opened 2020-07-02 · Closed 2023-02-22 · 62% similar
Microsec: Incorrect OCSP Delegated Responder Certificate
#2053131 ASSIGNED Ca Certificate Compliance Incident Externally Reported Incident Problem Reporting Failure Opened 2026-07-07 Still Open · 60% similar
TunTrust: OCSP responder "Unknown" of one Pre-certificate
#2049179 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Problem Reporting Failure Opened 2026-06-21 Still Open · 59% similar
CFCA: OCSP Service return unauthorized responses
#2048995 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Problem Reporting Failure Opened 2026-06-19 Still Open · 59% similar
eMudhra emSign PKI Services: OCSP Responder Returned "Unauthorized" for Some Pecertificates
#2047843 RESOLVED Ca Certificate Compliance Problem Reporting Failure Revocation Issue Opened 2026-06-16 · Closed 2026-07-09 · 59% similar
Certigna: Pre-certificates not recognised by the OCSP responder
#2049960 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Ccadb Disclosure Issue Opened 2026-06-24 Still Open · 58% similar
Actalis: Undisclosed Subordinate CA Certificate
#2048626 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Repository Issue Opened 2026-06-18 Still Open · 58% similar
Kamu SM: Incorrect CRL Served at SSL CRL Distribution Point

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action