Microsec insufficient support for unspecified (0) revocation reason
Microsec reported that its revocation tooling does not let customers initiate revocation without choosing a revocation reason, and it also does not automatically default to CRLReason “unspecified (0)” when no reason is provided. The bug cites BR 7.2.2, which requires CA-provided tools to make revocation reasons easy to specify and to default to no revocation reason. The incident was disclosed as a preliminary incident report, and the source of disclosure is stated to be the Apple Root Program. The thread provided does not include any remediation steps or closure; the case was still assigned at the time of the snapshot.
- Microsec identified that its revocation tools did not support defaulting to CRLReason unspecified (0) when no revocation reason was provided.
- Microsec representative — Opened the bug and posted a preliminary incident report describing the revocation-tooling issue and citing BR 7.2.2.
- Microsec representative — Noted that the source of the incident disclosure was the Apple Root Program.