Asseco DS / Certum: CP/CPS, Revocation Requests Mechanism, Certificate Problem Report, CRL and OCSP disruption during scheduled network maintenance
This case is a self-disclosed incident by Asseco Data Systems S.A. (Certum) describing a disruption during scheduled network maintenance on 2024-07-21. The disruption caused CP/CPS, the Revocation Requests Mechanism, the Certificate Problem Report service, CRL, and OCSP to be unavailable from the internet, which the CA stated violates BR requirements for 24x7 availability of these services and repository access. The CA reported that the issue was resolved within about 1–2 hours and that issuance of certificates was not affected. The CA provided a full incident report describing the scope of the maintenance, the incorrect route configuration as the root cause, and monitoring gaps that delayed detection. The CA also listed action items to improve monitoring and mitigation, including additional monitoring controls, CDN configuration changes for traffic switching, and external monitoring for Certificate Problem Report. The bug was marked RESOLVED with resolution FIXED, and the CA later stated that all action items were completed and monitoring continues for community questions.
- During scheduled network maintenance, Asseco DS/Certum’s CP/CPS, revocation request handling, Certificate Problem Report, CRL, and OCSP services became unavailable from the internet.
- The disruption was resolved within about 1–2 hours and the affected services were restored.
- The CA reported that all listed action items were completed and continued monitoring for questions.
- Asseco Data Systems S.A. — Filed a preliminary incident report stating the 2024-07-21 network disruption made CP/CPS, revocation requests/Certificate Problem Report, CRL, and OCSP unavailable from the internet, and said services were restored within 1–2 hours.
- Asseco Data Systems S.A. — Posted the full incident report with maintenance scope, timeline, root cause (incorrect route configuration), and monitoring/analysis details.
- Assecods representative — Stated there were no updates on the bug.
- Assecods representative — Stated there were no updates on the bug.
- Assecods representative — Provided an action-items update showing monitoring/mitigation tasks completed and due dates.
- Asseco Data Systems S.A. — Stated there were no updates on the bug.
- Assecods representative — Reported that all action items listed in the bug were completed and that monitoring continues.
- Mozilla representative — Said they would look at closing the bug on Friday, 30-Aug-2024.
- Assecods representative — Asked Mozilla to close the bug at the earliest convenience since there were no further questions or updates.