iTrusChina: CPR not responded within 24 hours (TLS BR Section 4.9.5)
iTrusChina reported that it was notified by the Google team about potentially mis-issued certificates used on iTrusChina test websites. iTrusChina said it responded to the Certificate Problem Report (CPR) email on the morning of 2024-10-28, which exceeded the 24-hour requirement. iTrusChina stated this was a violation of Section 4.9.5 of the TLS Baseline Requirements, which requires investigating a CPR and providing a preliminary report within 24 hours. The incident report attributes the delay to human negligence and inexperience, including failure to check the CPR email mailbox over the weekend. iTrusChina said it trained relevant staff and implemented a double-check mechanism, arranging at least two personnel to monitor CPRs and respond 7*24. The bug was marked RESOLVED with resolution FIXED, and iTrusChina requested closure after completing the disclosed action items. Mozilla indicated it would close the bug later that week unless there were questions or issues to discuss.
- Google emailed iTrusChina’s CPR mailbox about potentially mis-issued certificates.
- iTrusChina responded to the CPR email after the 24-hour window.
- iTrusChina disclosed a preliminary report in Bug 1927384 and confirmed the delayed response cause.
- iTrusChina reported completion of the action items and ongoing CPR monitoring staffing.
- iTrusChina requested incident report closure after remediation steps were completed.
- iTrusChina Co., Ltd. — iTrusChina stated it was notified that it did not respond to a CPR of mis-issuance within 24 hours.
- iTrusChina Co., Ltd. — iTrusChina provided an incident report describing the notification timing, the delayed response, the TLS BR Section 4.9.5 requirement, impact (certificates issued to iTrusChina itself), root cause (human negligence/inexperience), and action items (staff training and multiple personnel to monitor the CPR mailbox).
- iTrusChina Co., Ltd. — iTrusChina said it finished the action items and that at least two personnel would constantly monitor CPRs.
- Cooperjr representative — Peter Cooper questioned whether the stated root cause reflected the underlying process failures and asked about staffing, coverage, and the double-check mechanism.
- iTrusChina Co., Ltd. — iTrusChina responded that it tracks BR/policy changes, shares requirements with relevant teams, and implemented 7*24 email checking by two compliance personnel plus a senior manager.
- Cooperjr representative — Peter asked what the plan was for complying with the 24-hour response requirement and why it failed in this case.
- iTrusChina Co., Ltd. — iTrusChina said it had a workflow requiring a designated individual to check CPR emails 7*24, but the duty officer failed to check as stipulated, and it implemented a double-check mechanism.
- iTrusChina Co., Ltd. — iTrusChina submitted an incident report closure summary and requested closure, stating action items were completed.
- Mozilla representative — Mozilla said it would close the bug later that week unless there were questions or issues to discuss.