← Krajowa Izba Rozliczeniowa S.A. (KIR) cases
Bugzilla #1922572
Certificate Problem Report
KIR: Delayed revocation within seven (7) days for bug 1921598
RESOLVED
FIXED
Krajowa Izba Rozliczeniowa S.A. (KIR)
AI Summary
Krajowa Izba Rozliczeniowa S.A. (KIR) faced a significant incident involving the delayed revocation of the SZAFIR Trusted CA3 Intermediate CA certificate due to missing compliance identifiers. The revocation, mandated within seven days as per S/MIME BR, was not executed in time, affecting 8,355 end-user certificates across critical systems. The delay was attributed to infrastructure outages and complex processes involving multiple stakeholders. KIR has since implemented a remediation plan, including the issuance of a new CA and a commitment to improve compliance with revocation timelines.
Chronology
- Incident report posted regarding non-compliance
- Preliminary report indicating delayed revocation
- Affected certificate revoked
- Incident report closure summary posted
Participants
Piotr Grabowski
Tim Callan
Zacharias Björngren
External References
Similar Local Cases
KIR: Intermediate CA - SZAFIR Trusted CA3 - Certificate Policies extension - non-compliance
KIR: Intermediate CA - SZAFIR Trusted CA4 - Certificate Policies extension - non-compliance
KIR: Failed to respond a Certificate Problem Report within 24 hours
KIR S.A.: Invalid organizationName
KIR S.A.: DV certificates with locality name, organization name and stateOrProvinceName
KIR: Failure to disclose intermediate certificate within 7 days in ccadb
KIR: Failure to disclose intermediate certificate within 7 days in ccadb
KIR S.A.: CN domain not in SAN