← Saudi Data and Artificial Intelligence Authority (SDAIA) cases
Bugzilla #2058294 Ca Certificate Compliance Incident Self Reported Incident Revocation Issue Delayed Revocation

SDAIA delayed revocation of S/MIME certificates after audit coverage gap

ASSIGNED Saudi Data and Artificial Intelligence Authority (SDAIA)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns SDAIA’s delayed revocation of publicly trusted S/MIME subscriber certificates under Government CA 2 after an audit coverage gap was reported in Bug 2056942. SDAIA said the affected certificates had to be revoked, but some could not be revoked within the required 5-day timeframe because immediate revocation could disrupt critical internal government services. The initial report said 839 certificates had already been revoked and 172 remained, and later updates narrowed the remaining active set to 45 before all remaining certificates were revoked. SDAIA stated that issuance and renewal of S/MIME certificates under the affected hierarchy were suspended on 2026-07-20 and that it coordinated with Enterprise RAs and subscribers to replace certificates before revocation. The final closure summary says 331 certificates were not revoked within the 5-day period required by the S/MIME Baseline Requirements, and that the last affected certificate was revoked on 2026-08-16. SDAIA also said the remaining action to remove S/MIME trust from the hierarchy is tracked under the primary incident, Bug 2056942.

Model: gpt-5.4-mini Generated: 2026-07-27 21:12 UTC Revised: 2026-09-02 06:54 UTC Confidence: 0.98 18 comments
Chronology
  1. SDAIA identified the incident and suspended S/MIME issuance and renewal under the affected hierarchy.
  2. The non-compliance period began for delayed revocation of affected S/MIME certificates.
  3. SDAIA publicly disclosed the preliminary delayed revocation incident report.
  4. SDAIA revoked the last remaining affected certificates and ended the non-compliance period.
Thread Activity
  1. Sdaia representative — SDAIA opened a preliminary incident report saying 172 affected certificates remained unrevo ked and revocation was delayed because immediate revocation could cause operational impact.
  2. Sdaia representative — SDAIA filed a full incident report stating the delay was due to a risk-based decision to avoid significant operational impact while certificates were being replaced.
  3. Community commenter — A commenter said the report lacked root cause analysis and that certificates revoked after the deadline were part of the delayed revocation incident.
  4. Sdaia representative — SDAIA replied that it would update the report and clarified that the incident scope included all certificates revoked after the applicable revocation deadline.
  5. Sdaia representative — SDAIA confirmed that all remaining affected certificates had been revoked.
  6. Sdaia representative — SDAIA posted the closure summary stating that 331 certificates missed the 5-day revocation deadline and that the incident was complete.
  7. CCADB representative — CCADB incident reporting asked for final comments and said the report would be closed around 2026-09-07.
Participants
Sdaia representative Community commenter CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1877388 RESOLVED Delayed Revocation Incident Self Reported Incident Opened 2024-01-30 · Closed 2025-03-14 · 79% similar
Telekom Security: Revocation delay for TLS certificates with basicConstraints not marked as critical
#2011855 RESOLVED Delayed Revocation Opened 2026-01-22 · Closed 2026-05-11 · 78% similar
Firmaprofesional: Delayed revocation of TLS certificates affected by bug #2009941
#2016066 RESOLVED Delayed Revocation Opened 2026-02-11 · Closed 2026-03-30 · 78% similar
Firmaprofesional: Delayed preliminary response under BR 4.9.5 (Bug #2009941)
#1974435 RESOLVED Delayed Revocation Revocation Issue Opened 2025-06-27 · Closed 2025-08-19 · 77% similar
eMudhra emSign PKI Services : Delayed Revocation of TLS Certificates due to Policy Inconsistency.
#1905509 RESOLVED Delayed Revocation Opened 2024-06-29 · Closed 2025-05-08 · 76% similar
NETLOCK: CPR was not responded to in 24 hours
#2056942 ASSIGNED Ca Certificate Compliance Ca Documents Incident Self Reported Incident Opened 2026-07-22 Still Open · 74% similar
SDAIA: Missing S/MIME WebTrust audit coverage
#1861682 RESOLVED Ca Certificate Compliance Delayed Revocation Opened 2023-10-27 · Closed 2023-12-02 · 73% similar
SwissSign: EV delayed revocation
#1887888 RESOLVED Delayed Revocation Opened 2024-03-26 · Closed 2025-02-28 · 73% similar
Hongkong Post: Delayed revocation of TLS certificates with basicConstraints not marked as critical

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action