eMudhra emSign PKI Services: Delayed Revocation of SSL/TLS Certificates
On August 31, 2024, eMudhra received a notification from an external researcher regarding a potential compromise of four SSL/TLS certificates. The revocation of these certificates was delayed beyond the required 24-hour timeframe due to the request being misrouted to a general support email instead of the dedicated Certificate Problem Reporting contact. After escalating the issue, the certificates were revoked on September 2, 2024. eMudhra has since implemented corrective actions, including improved email routing and defined processes for handling non-responsive customers, to ensure compliance with TLS Baseline Requirements and prevent future delays.
- External researcher notified eMudhra of potential certificate compromise.
- eMudhra revoked the compromised SSL certificates.
- Emudhra representative — Incident report detailing the delay in revocation due to internal process failures.
- Google representative — Requested update and clarification on action items related to the incident.
- Emudhra representative — Provided a list of action items and their expected completion dates.
- Emudhra representative — Submitted report closure summary detailing incident root causes and remediation actions.