eMudhra emSign PKI Services: Delayed Revocation of TLS Certificates due to Policy Inconsistency.
eMudhra Technologies Limited issued TLS certificates with RSA key sizes exceeding 2048 bits, which were compliant with the CA/Browser Forum Baseline Requirements but misaligned with their own Certificate Policy/Certification Practice Statement (CP/CPS). An external report on June 19, 2025, prompted a reassessment of compliance, leading to a decision to revoke the affected certificates. Although the revocation exceeded the five-day window stipulated by the Baseline Requirements, all 449 unexpired certificates were revoked by June 26, 2025. The CA has since updated its internal procedures to ensure stricter adherence to policy alignment and timely revocation in similar future cases.
- External report received highlighting key size misalignment with CP/CPS.
- Revocation of all 449 unexpired certificates completed.
- Emudhra representative — Preliminary incident report submitted detailing the compliance issue and revocation decision.
- Emudhra representative — Full incident report submitted with detailed timeline and root cause analysis.
- Emudhra representative — Updated root cause analysis uploaded addressing internal decision-making and community engagement.