SDAIA preliminary incident report on delayed revocation of S/MIME certificates after audit coverage gap
SDAIA filed a preliminary incident report after identifying that S/MIME certificates issued under a hierarchy affected by the audit-coverage gap in Bug 2056942 must be revoked. SDAIA said it had revoked 839 affected certificates, but 172 certificates for 21 government agencies remained unrevoked. The report states that SDAIA could not complete revocation of the remaining certificates within the required 5-day timeline because immediate revocation could create operational and financial impact for the affected organizations. SDAIA said it was monitoring and following up with the affected organizations on mitigation and transition options. The report was self-disclosed and cites the S/MIME Baseline Requirements, Mozilla Root Store Policy, and CCADB incident reporting guidance.
- SDAIA disclosed that 172 affected S/MIME certificates remained unrevoked after an audit-coverage gap was identified.
- Sdaia representative — Submitted a preliminary incident report explaining the delayed revocation, the number of revoked and remaining certificates, and the operational risk to affected government agencies.