eMudhra emSign PKI Services: Key Blocking Mechanism Fails to Validate Historical Public Key Reuse.
eMudhra Technologies Limited reported an incident regarding their key blocking mechanism, which failed to validate previously issued certificates for public keys that had been revoked due to key compromise. This issue was identified by the Google team and affected three certificates. eMudhra has since revoked the affected certificates and implemented enhanced controls to ensure that the key blocking mechanism applies retroactively to all certificates. They have also adopted automated systems to improve the handling of revocations. The case has been resolved with all action items completed and a commitment to maintaining compliance with industry standards.
- eMudhra implemented a key blocking mechanism.
- Google team reported the key blocking issue.
- eMudhra requested closure of the incident.
- Emudhra representative — Incident report detailing the key blocking mechanism failure.
- Mozilla representative — Requested updates on remediation efforts.
- Mozilla representative — Inquired about closure of the case.
- Emudhra representative — Submitted closure summary and confirmed completion of all action items.