Firmaprofesional: Delayed revocation of TLS certificates affected by bug #2009941
Firmaprofesional identified a delayed revocation affecting a TLS Subscriber certificate and its issuing TLS Subordinate CA due to exceptional circumstances related to essential public healthcare services. The revocation could not be completed within the required timelines defined in the TLS Baseline Requirements. This delay was discovered during remediation activities related to a previously reported certificate misissuance (Bug #2009941). The CA scheduled the revocation for January 23, 2026, and completed it as planned. Following the incident, Firmaprofesional implemented several remediation actions to prevent future occurrences, including mandatory pre-issuance screening and updates to their Certificate Practice Statement.
- Non-compliance start date due to delayed revocation.
- Revocation of the affected certificates completed.
- Incident report closure requested after remediation actions completed.
- Logalty representative — Preliminary incident report submitted detailing the delayed revocation.
- Logalty representative — Confirmed completion of revocation for all affected certificates.
- Logalty representative — Final report submitted, requesting closure of the incident.