← iTrusChina Co., Ltd. cases
Bugzilla #1927675 Delayed Revocation

iTrusChina: CPR not responded within 24 hours (TLS BR Section 4.9.5)

RESOLVED FIXED iTrusChina Co., Ltd.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

iTrusChina reported that it was notified by the Google team about potentially mis-issued certificates used on iTrusChina test websites. iTrusChina said it responded to the Certificate Problem Report (CPR) email on the morning of 2024-10-28, which exceeded the 24-hour requirement. iTrusChina stated this was a violation of Section 4.9.5 of the TLS Baseline Requirements, which requires investigating a CPR and providing a preliminary report within 24 hours. The incident report attributes the delay to human negligence and inexperience, including failure to check the CPR email mailbox over the weekend. iTrusChina said it trained relevant staff and implemented a double-check mechanism, arranging at least two personnel to monitor CPRs and respond 7*24. The bug was marked RESOLVED with resolution FIXED, and iTrusChina requested closure after completing the disclosed action items. Mozilla indicated it would close the bug later that week unless there were questions or issues to discuss.

Model: gpt-5.4-nano Generated: 2026-06-13 21:13 UTC Revised: 2026-06-16 19:12 UTC Confidence: 0.50 9 comments
Chronology
  1. Google emailed iTrusChina’s CPR mailbox about potentially mis-issued certificates.
  2. iTrusChina responded to the CPR email after the 24-hour window.
  3. iTrusChina disclosed a preliminary report in Bug 1927384 and confirmed the delayed response cause.
  4. iTrusChina reported completion of the action items and ongoing CPR monitoring staffing.
  5. iTrusChina requested incident report closure after remediation steps were completed.
Thread Activity
  1. iTrusChina Co., Ltd. — iTrusChina stated it was notified that it did not respond to a CPR of mis-issuance within 24 hours.
  2. iTrusChina Co., Ltd. — iTrusChina provided an incident report describing the notification timing, the delayed response, the TLS BR Section 4.9.5 requirement, impact (certificates issued to iTrusChina itself), root cause (human negligence/inexperience), and action items (staff training and multiple personnel to monitor the CPR mailbox).
  3. iTrusChina Co., Ltd. — iTrusChina said it finished the action items and that at least two personnel would constantly monitor CPRs.
  4. Cooperjr representative — Peter Cooper questioned whether the stated root cause reflected the underlying process failures and asked about staffing, coverage, and the double-check mechanism.
  5. iTrusChina Co., Ltd. — iTrusChina responded that it tracks BR/policy changes, shares requirements with relevant teams, and implemented 7*24 email checking by two compliance personnel plus a senior manager.
  6. Cooperjr representative — Peter asked what the plan was for complying with the 24-hour response requirement and why it failed in this case.
  7. iTrusChina Co., Ltd. — iTrusChina said it had a workflow requiring a designated individual to check CPR emails 7*24, but the duty officer failed to check as stipulated, and it implemented a double-check mechanism.
  8. iTrusChina Co., Ltd. — iTrusChina submitted an incident report closure summary and requested closure, stating action items were completed.
  9. Mozilla representative — Mozilla said it would close the bug later that week unless there were questions or issues to discuss.
Participants
iTrusChina Co., Ltd. Cooperjr representative Mozilla representative
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#1656487 RESOLVED Delayed Revocation Opened 2020-07-31 · Closed 2023-02-22 · 72% similar
Izenpe: Failure to revoke within 5 days
#1886110 RESOLVED Delayed Revocation Opened 2024-03-19 · Closed 2025-02-14 · 71% similar
TWCA: Revocation delay for TLS certificates with non-critical basicConstraints
#1792111 RESOLVED Delayed Revocation Incident Opened 2022-09-22 · Closed 2023-02-22 · 71% similar
IdenTrust: Expired CRLs
#1734953 RESOLVED Delayed Revocation Opened 2021-10-08 · Closed 2024-06-30 · 71% similar
GoDaddy: CPR responses greater than 24 hours
#1886626 RESOLVED Delayed Revocation Opened 2024-03-20 · Closed 2024-06-01 · 71% similar
certSIGN: Delayed response to CPR
#1887941 RESOLVED Delayed Revocation Opened 2024-03-26 · Closed 2024-06-01 · 71% similar
Actalis: revocation delay for certificates issued with invalid RDN Order
#1861682 RESOLVED Ca Certificate Compliance Delayed Revocation Opened 2023-10-27 · Closed 2023-12-02 · 70% similar
SwissSign: EV delayed revocation
#1905509 RESOLVED Delayed Revocation Opened 2024-06-29 · Closed 2025-05-08 · 70% similar
NETLOCK: CPR was not responded to in 24 hours

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action