← Krajowa Izba Rozliczeniowa S.A. (KIR) cases
Bugzilla #1966006 Delayed Revocation

KIR: SZAFIR Trusted CA3 revocation status not updated in CCADB within 7 days

RESOLVED FIXED Krajowa Izba Rozliczeniowa S.A. (KIR)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Krajowa Izba Rozliczeniowa S.A. (KIR) revoked the subordinate/intermediate certificate “Szafir Trusted CA3” on March 5, 2025 as part of its planned decommissioning schedule. The revocation status was not updated in the CCADB within the 7-day window required by Section 6 of the Chrome Root Program Policy and by the CCADB Policy (Section 4 for subordinate CA certificates). The issue was first noticed and reported by the Chrome Root Program (CRP) Team, and KIR stated that the delay affected the CCADB status update. KIR reported that it updated its operational procedure for disclosing/updating CCADB statuses on May 13, 2025, and that WebPKI team training was completed by May 19, 2025. KIR also introduced routine monthly checks of CCADB entries and checks after significant PKI changes, completed by May 21, 2025. The bug was resolved as FIXED, and KIR requested closure stating that all action items had been completed.

Model: gpt-5.4-nano Generated: 2026-06-13 21:16 UTC Revised: 2026-06-16 19:17 UTC Confidence: 0.90 8 comments
Chronology
  1. KIR revoked the Szafir Trusted CA3 certificate as part of its planned decommissioning schedule.
  2. KIR’s WebPKI team began investigating after notification from the Chrome Root Program Team.
  3. KIR updated its operational procedure for disclosing/updating CCADB statuses.
  4. KIR completed training for WebPKI team members on the updated operational procedure.
  5. KIR completed implementation of routine monthly CCADB entry reviews and checks after significant PKI changes.
Thread Activity
  1. Kir representative — KIR provided a preliminary incident report stating the subordinate certificate revocation was not updated in CCADB within the required timeline and that a full incident report would follow.
  2. Kir representative — KIR submitted the full incident report, describing the non-compliance period, stating the issue was first noticed by the Chrome Root Program Team, and identifying the root cause as a CCADB update failure due to an overly general internal procedure.
  3. Google representative — The Chrome Root Program commented that the incident report needed updates (e.g., more complete policy references, timeline details, and related incidents) and asked for improvements to the root cause and action items sections.
  4. Kir representative — KIR responded by updating the report with additional policy references, correcting/expanding the timeline (including notification timing), and adding/adjusting related incidents and action items.
  5. Kir representative — KIR stated that all action items had been completed and that there were no further updates.
  6. CCADB representative — CCADB incident reporting provided guidance for closing the report.
  7. Kir representative — KIR posted a report closure summary describing the incident, root causes, remediation, and requesting closure after confirming all action items were implemented.
  8. CCADB representative — CCADB issued a final call for comments and stated the report would be closed around 2025-07-01.
Participants
Kir representative Google representative CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1922572 RESOLVED Delayed Revocation Opened 2024-10-03 · Closed 2025-05-08 · 83% similar
KIR: Delayed revocation within seven (7) days for bug 1921598
#1709872 RESOLVED Delayed Revocation Opened 2021-05-06 · Closed 2023-02-22 · 80% similar
KIR S.A.: Delayed revocations of certificates
#2025538 RESOLVED Delayed Revocation Opened 2026-03-23 · Closed 2026-04-23 · 77% similar
Firmaprofesional: Delayed weekly updates and responses on open incident reports
#1986911 RESOLVED Delayed Revocation Opened 2025-09-04 · Closed 2025-10-22 · 76% similar
SECOM: No updated CRLs published for Cybertrust Japan SureMail CA G4
#2004698 RESOLVED Delayed Revocation Opened 2025-12-08 · Closed 2026-01-15 · 76% similar
NAVER Cloud Trust Services: Failure to respond to CPR within 24 hours
#1905509 RESOLVED Delayed Revocation Opened 2024-06-29 · Closed 2025-05-08 · 75% similar
NETLOCK: CPR was not responded to in 24 hours
#1947691 RESOLVED Delayed Revocation Opened 2025-02-12 · Closed 2025-08-19 · 75% similar
NETLOCK: Bug 1891331 replacement - delayed revocation -
#2009043 RESOLVED Delayed Revocation Opened 2026-01-07 · Closed 2026-02-19 · 71% similar
Chunghwa Telecom: Delayed disclosure to Bug 2008782 GTLSCA Audit Incident Report #1 - mass certificate revocation plan

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action