← Apple Inc. cases
Bugzilla #1955365 Self Reported Incident

Apple: Public Key Reuse

RESOLVED FIXED Apple Inc.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Apple reported a certificate issuance incident after identifying a race condition in its certificate issuance systems. Apple stated that the race condition could cause multiple certificates to be issued for the same public key when issuance requests are made simultaneously (or within a very small time period). Apple said 47 certificates were impacted in the preliminary report and later stated 44 certificates were impacted in the full incident report, and that all impacted certificates were revoked. Apple also reported that it partially stopped issuance by reaching out to the affected customer to stop approving certificates while a fix was worked on, and determined it was not necessary to stop all issuance due to low volume and mitigation of the primary group. Apple described remediation including implementing a two-stage database transaction for public key use, adding alerting for public key reuse errors, and updating its CPS. Apple requested closure after stating that the action items were completed and that remediation was sufficient to prevent a similar issue in the future.

Model: gpt-5.4-nano Generated: 2026-06-13 15:14 UTC Revised: 2026-06-16 18:05 UTC Confidence: 0.90 10 comments
Chronology
  1. Apple updated its Apple Public CPS to version 5.0 with a statement in Section 4.6 about not providing certificate renewal that includes reuse of a public key.
  2. Apple identified a race condition in its certificate issuance systems that could lead to multiple certificates being issued for the same public key.
  3. Apple revoked the impacted certificates after identifying the incident.
  4. Apple published a preliminary incident report to Bugzilla and updated RA hosts with a fix for the key reuse race condition.
  5. Apple published the full incident report with timeline, root cause analysis, and impact details.
  6. Apple posted a report closure summary stating remediation and action items were completed and requested closure.
Thread Activity
  1. Apple representative — Apple provided a preliminary incident report describing a race condition that could issue multiple certificates to the same public key and stated impacted certificates were revoked.
  2. Community commenter — A community member asked about encouraging CA adoption of narrower voluntary policies than the BRs and commented on transparency.
  3. Mozilla representative — Mozilla responded that the process can discourage voluntary higher standards and suggested alternative channels/resources such as the Mozilla wiki.
  4. Apple representative — Apple posted the full incident report with impact (44 certificates), timeline, root cause analysis, and remediation steps including a fix to RA hosts.
  5. Apple representative — Apple stated it was working toward a final action item and asked to set the next update date to 4/28/2025.
  6. Apple representative — Apple updated a chart showing completed action items including implementing fixes, adding automated alerting, and completing a CPS update.
  7. Apple representative — Apple posted a report closure summary stating remediation was completed (two-stage database transaction, alerting, and CPS update) and requested closure.
  8. CCADB representative — CCADB issued a final call for comments/questions and noted the incident would be closed if no further input was received.
  9. Google representative — Google commented that the report adhered to CCADB IRGs and praised the self-reporting transparency and proactive accountability.
Participants
Apple representative Community commenter Mozilla representative CCADB representative Google representative
External References
Similar Local Cases
#1841534 RESOLVED Self Reported Incident Certificate Misissuance Opened 2023-07-03 · Closed 2023-08-30 · 97% similar
Apple: TLS certificates issued outside the TTL of the CAA record
#1588001 RESOLVED Self Reported Incident Opened 2019-10-11 · Closed 2023-02-22 · 95% similar
Apple: OCSP responders return responses with incorrect issuer
#1959733 RESOLVED Self Reported Incident Opened 2025-04-10 · Closed 2025-07-16 · 85% similar
CFCA: Failed to respond a Certificate Problem Report within 24 hours which violates Section 4.9.5 of the TLS BRs
#1950144 RESOLVED Incident Self Reported Incident Opened 2025-02-24 · Closed 2026-06-11 · 83% similar
DigiCert: Threat of legal action to stifle Bugzilla discourse
#1950574 RESOLVED Self Reported Incident Opened 2025-02-26 · Closed 2025-09-15 · 83% similar
SECOM: S/MIME CA Modified Opinion Report of Cybertrust Japan (CTJ)
#1981680 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Linting Quality Issue Opened 2025-08-07 · Closed 2025-09-26 · 83% similar
TunTrust: SSL OV mis-issuance against CP/CPS (Email attribute)
#2009525 RESOLVED Self Reported Incident Opened 2026-01-09 · Closed 2026-03-08 · 81% similar
Amazon Trust Services: Additional CRL Characteristics Desired in CP/CPS
#1904041 RESOLVED Ca Documents Self Reported Incident Opened 2024-06-21 · Closed 2025-07-01 · 78% similar
NETLOCK: Intermediate CA Certificate not disclosed to CCADB

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action