← eMudhra Technologies Limited cases
Bugzilla #1916478 Delayed Revocation

eMudhra emSign PKI Services: Delayed Revocation of SSL/TLS Certificates

RESOLVED FIXED eMudhra Technologies Limited
AI Summary

On August 31, 2024, eMudhra received a notification regarding a potential compromise of four SSL/TLS certificates. The required revocation was delayed due to the request being misrouted to a general support email instead of the dedicated Certificate Problem Reporting contact. Additionally, the affected customer did not respond promptly, further complicating the situation. The certificates were eventually revoked on September 2, 2024, without any reported misuse during the delay. eMudhra has since implemented corrective actions, including improved email routing and defined escalation processes for non-responsive customers to ensure compliance with TLS Baseline Requirements.

Model: gpt-4o-mini Generated: 2026-06-13 21:25 UTC Confidence: 0.90
Chronology
  1. Researcher submitted revocation request via general support email.
  2. eMudhra became aware of the issue and started internal investigation.
  3. Customer acknowledged compromise; certificates were revoked.
Participants
Naveen Kumar ML Chris Clements Aaron Zandberg Hanno Böck Ben Wilson
External References
Similar Local Cases
#1974435 RESOLVED Delayed Revocation Opened 2025-06-27 · Closed 2025-08-19 · 58% similar
eMudhra emSign PKI Services : Delayed Revocation of TLS Certificates due to Policy Inconsistency.
#1891331 RESOLVED Delayed Revocation Opened 2024-04-13 · Closed 2025-03-10 · 50% similar
NETLOCK: Policy Qualifiers other than id-qt-cps is included in TLS certificates - delayed revocation
#1872738 RESOLVED Delayed Revocation Opened 2024-01-02 · Closed 2025-02-14 · 49% similar
Buypass: Delayed revocation of TLS certificates
#1877388 RESOLVED Delayed Revocation Opened 2024-01-30 · Closed 2025-03-14 · 49% similar
Telekom Security: Revocation delay for TLS certificates with basicConstraints not marked as critical
#1652610 RESOLVED Delayed Revocation Opened 2020-07-13 · Closed 2023-02-22 · 49% similar
SECOM: Delayed Revocation of CA Certificate with OCSP EKU Issue
#1707229 RESOLVED Delayed Revocation Opened 2021-04-23 · Closed 2023-02-22 · 49% similar
SECOM: Delayed Revocation of non-technically constrained FUJIFILM Certificates
#1647099 RESOLVED Delayed Revocation Opened 2020-06-20 · Closed 2023-02-22 · 49% similar
Camerfirma: Delayed revocations related to Invalid authorityKeyIdentifier - recurrent incident
#1861682 RESOLVED Delayed Revocation Opened 2023-10-27 · Closed 2023-12-02 · 48% similar
SwissSign: EV delayed revocation

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action