Telia delayed revocation of seven misissued certificates tied to incident 1896108
This case concerns Telia CA’s delayed revocation of seven end-entity TLS certificates associated with incident 1896108. Telia opened the bug to report that the certificates were misissued and were not revoked within the required five-day timeframe under the Baseline Requirements and Telia’s own CP/CPS. Telia said the delay was caused by subscriber-side operational constraints, including planned change procedures, limited availability over a holiday period, and one subscriber initially refusing to replace a certificate. Over time, Telia reported each revocation as it completed, and it also posted remediation items to reinforce revocation handling and prevent future delays. Mozilla later said the bug would remain open for a period while incident-reporting and compliance work continued, and Telia eventually filed a closure summary stating that all action items were complete.
- Telia reported seven misissued certificates had not been revoked within five days.
- Telia revoked three of the affected certificates.
- One additional affected certificate was revoked.
- Telia reported one more certificate revoked and published remediation action items.
- Two pending revocations were completed.
- Telia filed a closure summary stating the incident response and remediation were complete.
- Teliacompany representative — Telia opened the incident report, said seven certificates missed the five-day revocation deadline, and listed revocation and follow-up action items.
- Teliacompany representative — Telia said three certificates had been revoked and that it would continue updates until all were revoked.
- HARICA — A commenter asked for more detail on the subscriber types and challenges behind the delayed revocation.
- Teliacompany representative — Telia explained the delay as a holiday/timing issue, subscriber capacity limits, and one subscriber initially refusing replacement.
- Teliacompany representative — Telia reported another certificate revoked and said it would address action items in a full incident report for bug 1896108.
- Teliacompany representative — Telia reported one more revocation, listed preventive action items, and identified the remaining delayed certificates.
- Teliacompany representative — Telia said the two pending revocations had been completed and marked the revocation action item complete.
- Teliacompany representative — Telia said the remaining open action items had been completed.
- Teliacompany representative — Telia clarified that the root cause was its decision not to revoke in time and said it had updated internal instructions and processes.
- Mozilla representative — Mozilla said the bug would remain open until at least 2025-02-01 while incident-reporting and compliance work continued.
- Teliacompany representative — Telia posted a closure summary describing the incident, root cause, remediation, and commitment summary.