← DigiCert cases
Bugzilla #1910805
Delayed Revocation
DigiCert: Delayed revocation of 1910322
CLOSED
DigiCert
AI Summary
DigiCert experienced a significant incident involving the delayed revocation of over 83,000 certificates due to a validation flaw. Initially required to revoke these certificates within 24 hours, DigiCert extended the revocation period to 120 hours after determining that some customers faced exceptional circumstances. This decision led to a flood of requests for delays, complicating the situation further. DigiCert has since implemented measures to improve its incident response processes and promote automation among its customers to prevent similar issues in the future.
Chronology
- DigiCert files preliminary incident report.
- DigiCert receives notice of a Temporary Restraining Order (TRO) against revocations.
- All affected certificates are revoked.
Participants
Jeremy Rowley
DigiCert Team
Mozilla Community
External References
Similar Local Cases
Digicert: Delayed Revocation for bug 1894560
DigiCert: Delay of revocation for EV audit inconsistency incident
DigiCert: Delayed revocation of IV certificates
Microsec: Delayed revocation of the misissued certificates
D-TRUST: Delayed revocation of EV certificates
SECOM: Delayed Revocation of non-technically constrained FUJIFILM Certificates
NETLOCK: Policy Qualifiers other than id-qt-cps is included in TLS certificates - delayed revocation
SSL.com: Delayed revocation of 53 certificates affected by bug #1750631