← Saudi Data and Artificial Intelligence Authority (SDAIA) cases
Bugzilla #2058294 Ca Certificate Compliance Incident Self Reported Incident Delayed Revocation

SDAIA preliminary incident report on delayed revocation of S/MIME certificates after audit coverage gap

UNCONFIRMED Saudi Data and Artificial Intelligence Authority (SDAIA)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

SDAIA filed a preliminary incident report after identifying that S/MIME certificates issued under a hierarchy affected by the audit-coverage gap in Bug 2056942 must be revoked. SDAIA said it had revoked 839 affected certificates, but 172 certificates for 21 government agencies remained unrevoked. The report states that SDAIA could not complete revocation of the remaining certificates within the required 5-day timeline because immediate revocation could create operational and financial impact for the affected organizations. SDAIA said it was monitoring and following up with the affected organizations on mitigation and transition options. The report was self-disclosed and cites the S/MIME Baseline Requirements, Mozilla Root Store Policy, and CCADB incident reporting guidance.

Model: gpt-5.4-mini Generated: 2026-07-27 21:12 UTC Confidence: 0.98 1 comment
Chronology
  1. SDAIA disclosed that 172 affected S/MIME certificates remained unrevoked after an audit-coverage gap was identified.
Thread Activity
  1. Sdaia representative — Submitted a preliminary incident report explaining the delayed revocation, the number of revoked and remaining certificates, and the operational risk to affected government agencies.
Participants
Sdaia representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1861682 RESOLVED Ca Certificate Compliance Delayed Revocation Opened 2023-10-27 · Closed 2023-12-02 · 71% similar
SwissSign: EV delayed revocation
#1596744 RESOLVED Delayed Revocation Incident Opened 2019-11-15 · Closed 2024-06-30 · 71% similar
Izenpe: Intermediate CA certificates not listed in audit report
#1598608 RESOLVED Delayed Revocation Incident Opened 2019-11-22 · Closed 2023-02-22 · 71% similar
Izenpe: intermediate certificates not revoked within BR time period
#1598319 RESOLVED Delayed Revocation Self Reported Incident Opened 2019-11-21 · Closed 2023-02-22 · 71% similar
Buypass: intermediate certificates not revoked within BR time period
#1600158 RESOLVED Ca Certificate Compliance Delayed Revocation Opened 2019-11-28 · Closed 2023-02-22 · 70% similar
Asseco DS / Certum: Failure to revoke intermediate certificates within the BR time period
#1877388 RESOLVED Delayed Revocation Incident Self Reported Incident Opened 2024-01-30 · Closed 2025-03-14 · 69% similar
Telekom Security: Revocation delay for TLS certificates with basicConstraints not marked as critical
#2034359 ASSIGNED Delayed Revocation Self Reported Incident Opened 2026-04-23 Still Open · 69% similar
SwissSign: Delayed revocation related to Bugzilla 2033000
#1391000 RESOLVED Ca Certificate Compliance Incident Revocation Issue Opened 2017-08-16 · Closed 2023-02-22 · 69% similar
IdenTrust: Non-BR-Compliant Certificate Issuance

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action