← Microsec Ltd. cases
Bugzilla #1925239
Certificate Problem Report
Microsec: Expired Certificates on test Pages for Revocation
RESOLVED
FIXED
Microsec Ltd.
AI Summary
Microsec Ltd. reported an issue regarding expired certificates on their test pages for revoked certificates. The expired certificates rendered these pages ineffective for testing the CA revocation service. The problem was identified on October 14, 2024, following a notification from Google. Microsec took immediate action to replace the expired certificates and implemented measures to prevent future occurrences, including automated monitoring and regular manual checks. The case has been resolved with the implementation of corrective actions.
Chronology
- Microsec received notification about expired certificates on test pages.
- Incident report opened in Bugzilla.
- Automated tests successfully implemented.
Participants
szoke.sandor@microsec.hu
bwilson@mozilla.com
External References
Similar Local Cases
MICROSEC: Incident report - No OCSP status response for 2 Precertificates
Microsec: Late response to a CPR
Microsec: CT Logging mistakes
Telia: Certificates with RSA keys where modulus is not divisible by 8
CFCA: The wrong status of OCSP
Let's Encrypt: Early CRL Removal Incident
Let's Encrypt: Certificates issued to Elliptic Curve Debian Weak Keys
SSL.com: Issuance of an EV TLS certificate with incorrect O Field Value