← Certainly LLC cases
Bugzilla #2052399 Incident Self Reported Incident Repository Issue Remediation Tracking Closure Request

Certainly LLC: Expired certificates on BR §2.2 test websites; incident report closed after remediation

RESOLVED FIXED Certainly LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Certainly LLC self-reported that its BR §2.2 test websites served expired certificates on the “valid” and “revoked” pages after the certificates expired on 2026-06-08 and were not renewed for 23 days. The report said the issue was caused by an unpinned upstream dependency that introduced a breaking CLI change, together with a monitoring misconfiguration that suppressed TLS validation alerts. Certainly stated there was no misissuance and that certificate issuance, revocation, and CRL services were unaffected; the problem was limited to the availability and correctness of the test websites. The company reported that all remediation action items were completed, including pinning the dependency, fixing monitoring, adding expiry pre-alerting, and decommissioning the legacy monitoring tool. The thread then moved to closure, with CCADB posting a final call for comments and the report closure summary stating that all disclosed action items were complete and closure was requested. The bug is now RESOLVED/FIXED.

Model: gpt-5.4-mini Generated: 2026-07-04 18:31 UTC Revised: 2026-08-09 07:00 UTC Confidence: 0.98 7 comments
Chronology
  1. BR §2.2 test website certificates expired and the “valid” and “revoked” sites presented expired certificates for 23 days.
  2. Emergency change deployed; all six BR §2.2 test website certificates were re-issued and sites restored/verified externally.
  3. All five remediation action items were completed, including migration to configuration-as-code monitoring and decommissioning the legacy tool.
Thread Activity
  1. Fastly representative — Filed a full incident report describing expired certificates on the “valid” and “revoked” test sites, attributing it to an unpinned upstream dependency breaking change plus suppressed monitoring alerts, and stating an emergency fix re-issued all six certificates on 2026-07-02.
  2. Fastly representative — Provided a weekly update that the external monitor configuration audit was completed and the monitoring migration and expiry pre-alerting work remained in progress.
  3. Fastly representative — Posted a weekly update stating remediation remained on track for the 2026-07-31 date.
  4. Fastly representative — Reported that all action items were complete except decommissioning the legacy monitoring tool, and that the configuration-as-code replacement was deployed with alerting operational.
  5. Fastly representative — Submitted a closure summary stating all disclosed action items were complete and requesting closure of the incident report.
  6. CCADB representative — Posted a final call for comments or questions and said the incident report would be closed around 2026-08-07.
Participants
Fastly representative CCADB representative Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2061909 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Revocation Issue Opened 2026-08-08 Still Open · 88% similar
Certainly: Test Website Certificate Renewal Failure Following Production Deployment Drift
#1968836 RESOLVED Incident Self Reported Incident Opened 2025-05-28 · Closed 2025-08-26 · 87% similar
Certainly: Sample Websites Unavailable
#2052085 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Audit Finding Opened 2026-07-02 Still Open · 87% similar
Certainly: Missing audit log entries for certificates issued during capacity testing
#2051459 ASSIGNED Self Reported Incident Incident Vulnerability Disclosure Remediation Tracking Opened 2026-06-30 Still Open · 84% similar
NETLOCK: OCSP Service Returning Error for Issued Certificate
#2048626 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Repository Issue Opened 2026-06-18 · Closed 2026-08-04 · 82% similar
Kamu SM: Incorrect CRL Served at SSL CRL Distribution Point
#1999850 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Revocation Issue Opened 2025-11-13 · Closed 2026-07-01 · 82% similar
Microsoft PKI Services: OCSP Non-Compliance
#2048370 RESOLVED Self Reported Incident Delayed Revocation Remediation Tracking Opened By Ca Opened 2026-06-17 · Closed 2026-08-08 · 81% similar
Sectigo: Delay in some OCSP response signing due to application restart loop
#2048444 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-06-18 · Closed 2026-08-04 · 81% similar
IdenTrust: End Entity TLS certificate mis-issuance against CP/CPS (IdenTrust certificate policy OIDs)

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action