← certSIGN cases
Bugzilla #2025318
Certificate Problem Report
certSIGN: delay in updating a Bugzilla ticket
RESOLVED
FIXED
certSIGN
AI Summary
certSIGN experienced a delay in updating a Bugzilla ticket related to an open bug (Bug 2016672) that was completed but lacked a Closure Report or a 'Next update' date for over 7 days. This delay was identified as a non-compliance issue under the Common CA Database Incident Reporting Guidelines. The root cause was attributed to a procedural issue that relied on a single person for ticket management, leading to missed actions and expired notifications. certSIGN has since implemented corrective actions to enhance their incident management processes and prevent future occurrences.
Chronology
- Non-compliance start date identified
- Non-compliance identified
- Closure report added to the ticket
- Final report closure summary submitted
Participants
Gabriel PETCU
Wayne
chrome-root-program@google.com
incident-reporting@ccadb.org
External References
Similar Local Cases
certSIGN: Missing certificate from the list of bad order subject attributtes
certSIGN: Incorrect data in stateOrProvinceName
certSIGN: certificates with delayed SCT signature
certSIGN: Certificates with incorrect Subject attribute order
certSIGN: Delayed response to CPR
certSIGN: Delayed revocation
certSIGN: Findings in 2025 ETSI Audit - Audit Incident Report #4 – Expired cert with bad order of attributes
Apple: Public Key Reuse