SDAIA delayed revocation of S/MIME certificates after audit coverage gap
This case concerns SDAIA’s delayed revocation of publicly trusted S/MIME subscriber certificates under Government CA 2 after an audit coverage gap was reported in Bug 2056942. SDAIA said the affected certificates had to be revoked, but some could not be revoked within the required 5-day timeframe because immediate revocation could disrupt critical internal government services. The initial report said 839 certificates had already been revoked and 172 remained, and later updates narrowed the remaining active set to 45 before all remaining certificates were revoked. SDAIA stated that issuance and renewal of S/MIME certificates under the affected hierarchy were suspended on 2026-07-20 and that it coordinated with Enterprise RAs and subscribers to replace certificates before revocation. The final closure summary says 331 certificates were not revoked within the 5-day period required by the S/MIME Baseline Requirements, and that the last affected certificate was revoked on 2026-08-16. SDAIA also said the remaining action to remove S/MIME trust from the hierarchy is tracked under the primary incident, Bug 2056942.
- SDAIA identified the incident and suspended S/MIME issuance and renewal under the affected hierarchy.
- The non-compliance period began for delayed revocation of affected S/MIME certificates.
- SDAIA publicly disclosed the preliminary delayed revocation incident report.
- SDAIA revoked the last remaining affected certificates and ended the non-compliance period.
- Sdaia representative — SDAIA opened a preliminary incident report saying 172 affected certificates remained unrevo ked and revocation was delayed because immediate revocation could cause operational impact.
- Sdaia representative — SDAIA filed a full incident report stating the delay was due to a risk-based decision to avoid significant operational impact while certificates were being replaced.
- Community commenter — A commenter said the report lacked root cause analysis and that certificates revoked after the deadline were part of the delayed revocation incident.
- Sdaia representative — SDAIA replied that it would update the report and clarified that the incident scope included all certificates revoked after the applicable revocation deadline.
- Sdaia representative — SDAIA confirmed that all remaining affected certificates had been revoked.
- Sdaia representative — SDAIA posted the closure summary stating that 331 certificates missed the 5-day revocation deadline and that the incident was complete.
- CCADB representative — CCADB incident reporting asked for final comments and said the report would be closed around 2026-09-07.