eMudhra emSign PKI Services: Issue with revocation as part of automated reissuance
On January 8, 2025, eMudhra identified a misconfiguration in its certificate lifecycle management system that led to the erroneous revocation of 311 domain certificates. This issue arose during an automated reissuance process, where valid certificates were mistakenly revoked and marked with a 'Key Compromise' reason instead of 'Superseded'. Despite the revocation, the active replacement certificates remained valid, minimizing customer impact. eMudhra took immediate corrective actions, including fixing the subroutine responsible for the error, enhancing validation processes, and improving customer communication. The incident was resolved with all action items completed by March 31, 2025.
- eMudhra detected an issue with the automated revocation process.
- All corrective actions were completed to prevent future misconfigurations.
- Emudhra representative — Incident report detailing the misconfiguration and its impact was submitted.
- Emudhra representative — All comments were reviewed, and responses to key points were provided.
- Emudhra representative — Closure summary report was submitted, detailing the incident and remediation actions.