← Microsec Ltd. cases
Bugzilla #1925239 Self Reported Incident

Microsec: Expired Certificates on test Pages for Revocation

RESOLVED FIXED Microsec Ltd.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Microsec reported an incident involving its revocation test web pages: certificates protecting those pages had expired, making the pages not applicable for testing the CA revocation service. The issue was triggered when Microsec received an email from Chris Clements (Google) reporting a potential problem with two revoked test pages; Microsec then investigated and found three affected test web pages. Microsec corrected the problem by generating new keys and issuing new certificates with longer lifetimes, then replacing the certificates on the test web pages and notifying the affected party. Microsec attributed the root cause to the focus on automatic renewal for VALID test pages, which led to the expired certificates not being replaced on time, and to a separate issue related to the REVOKED certificate on the new dedicated hierarchy. In follow-up comments, Microsec described plans to improve monitoring and reconfigure its monitoring system to properly handle revoked test certificates, and it provided multiple status reports on process reviews and automation/testing changes. The bug was resolved as FIXED, with a closing status report dated 2025-01-10 and a note that Mozilla would close it on or about 13-Jan-2025.

Model: gpt-5.4-nano Generated: 2026-06-13 21:15 UTC Revised: 2026-06-16 19:18 UTC Confidence: 0.86 10 comments
Chronology
  1. Microsec received an external report that revoked test pages were potentially problematic due to expired certificates.
  2. Microsec opened a JIRA ticket to manage the incident.
  3. Microsec provided a closing status report indicating related monitoring and manual checks had been completed or terminated.
Thread Activity
  1. Microsec representative — Opened an incident report in Bugzilla describing expired certificates on revoked test pages and the corrective actions taken (new keys, new longer-lifetime certificates, and replacement on the test pages).
  2. Community commenter — Asked whether Microsec was considering automated monitoring (e.g., daily) to check expected certificate status on all deployed test web pages.
  3. Microsec representative — Responded that Microsec uses Nagios and daily certificate monitoring, but that warnings were turned off for revoked test certificates in this special case; stated it would reconfigure monitoring to handle these revoked test certificates properly.
  4. Microsec representative — Provided a status report listing review of external requirements and internal processes, clarifying requirements for test websites, and action items including issuing new long-lifetime REVOKED test certificates and improving supervision/automation.
  5. Microsec representative — Provided a status report describing completed external requirement review and planned changes to test website organization and automation for certificate exchange and daily testing.
  6. Microsec representative — Provided another status report with updates to test website setup, improved automatic testing, and action item statuses.
  7. Microsec representative — Reported decisions for REVOKED/EXPIRED test sites (manual renewal triggers and manual revocation) and continued work on audit log processing and weekly manual checks.
  8. Microsec representative — Submitted a closing status report stating log entries had been processed since end of November 2024 and that weekly manual checks were terminated after automated tests succeeded on 2025-01-01.
  9. Mozilla representative — Indicated the case would be closed on or about Monday, 13-Jan-2025.
Participants
Microsec representative Community commenter Mozilla representative
External References
Similar Local Cases
#1865880 RESOLVED Self Reported Incident Opened 2023-11-21 · Closed 2024-02-14 · 94% similar
Microsec: Findings in 2023 Audit
#2005939 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-12-14 · Closed 2026-03-13 · 87% similar
Microsec: CT Logging mistakes
#2013576 RESOLVED Self Reported Incident Certificate Misissuance Opened 2026-01-30 · Closed 2026-02-27 · 87% similar
Microsec: "DV valid" test website certificate issued under incorrect root
#1622539 RESOLVED Self Reported Incident Opened 2020-03-14 · Closed 2023-02-22 · 79% similar
Microsec: Issuance of 2 IVCP precertificates without givenName, surName, localityName fields
#1952519 RESOLVED Self Reported Incident Repository Issue Opened 2025-03-07 · Closed 2025-05-08 · 79% similar
Microsec: Inconsistent Disclosure of S/MIME BR Audit Information in CCADB
#1742704 RESOLVED Incident Self Reported Incident Opened 2021-11-23 · Closed 2024-05-09 · 69% similar
Let's Encrypt: Potential Denial of Service against websites with broad private key reuse
#1740493 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-11-10 · Closed 2023-02-22 · 69% similar
Sectigo: Failure to block disallowed LDH labels in domain names
#1676440 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-11-10 · Closed 2023-02-22 · 69% similar
NetLock: Cumulative report connected to EV verification

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action