← Microsec Ltd. cases
Bugzilla #1887110 Delayed Revocation

Microsec: Delayed revocation of the misissued certificates

RESOLVED FIXED Microsec Ltd.
AI Summary

Microsec Ltd. faced a situation where they misissued 46 EV certificates lacking a CPSuri link. While 44 of these certificates were revoked within the mandated 5-day period, two certificates used in a PSD2 network could not be replaced in time due to the complexity of the network and the number of partners involved. This led to a request for an extension of the revocation deadline, which was granted under exceptional circumstances. Microsec has since committed to improving their Certificate Policy Statement (CPS) to prevent similar issues in the future and has established a new dedicated CA hierarchy for issuing PSD2 client authentication certificates.

Model: gpt-4o-mini Generated: 2026-06-13 21:15 UTC Confidence: 0.95
Chronology
  1. Microsec received a report of a potentially misissued certificate.
  2. A second report was received, prompting immediate action.
  3. 44 misissued certificates were revoked.
  4. The last two misissued certificates were revoked after an extension.
  5. Closure summary provided, detailing improvements and commitments.
Participants
dr. Sándor SZŐKE Mike Shaver Tim Callan Dimitris Zacharopoulos Ben Wilson
External References
Similar Local Cases
#1887705 RESOLVED Delayed Revocation Opened 2024-03-25 · Closed 2024-09-12 · 64% similar
Entrust: Delayed revocation of clientAuth TLS Certificates without serverAuth EKU
#1877388 RESOLVED Delayed Revocation Opened 2024-01-30 · Closed 2025-03-14 · 63% similar
Telekom Security: Revocation delay for TLS certificates with basicConstraints not marked as critical
#1887888 RESOLVED Delayed Revocation Opened 2024-03-26 · Closed 2025-02-28 · 57% similar
Hongkong Post: Delayed revocation of TLS certificates with basicConstraints not marked as critical
#1651465 RESOLVED Delayed Revocation Opened 2020-07-08 · Closed 2023-02-22 · 56% similar
HARICA: Delayed revocation for non-BR-compliant CA Certificates within 7 days
#1872738 RESOLVED Delayed Revocation Opened 2024-01-02 · Closed 2025-02-14 · 55% similar
Buypass: Delayed revocation of TLS certificates
#1886665 RESOLVED Delayed Revocation Opened 2024-03-21 · Closed 2025-02-28 · 55% similar
Hongkong Post: Delayed revocation of TLS certificates with Certificate Policies extension problem
#1707229 RESOLVED Delayed Revocation Opened 2021-04-23 · Closed 2023-02-22 · 50% similar
SECOM: Delayed Revocation of non-technically constrained FUJIFILM Certificates
#1891331 RESOLVED Delayed Revocation Opened 2024-04-13 · Closed 2025-03-10 · 50% similar
NETLOCK: Policy Qualifiers other than id-qt-cps is included in TLS certificates - delayed revocation

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action