DigiCert: Underscores - Canadian Imperial Bank of Commerce
Categories
(CA Program :: CA Certificate Compliance, task)
Tracking
(Not tracked)
People
(Reporter: jeremy.rowley, Assigned: brenda.bernal)
Details
(Whiteboard: [ca-compliance] [ov-misissuance])
| Assignee | ||
Comment 1•7 years ago
|
||
Additional input from the customer below:
"We will be able to replace the certificates. The issue is that we are not given enough time to do it. For one application the underscore will be removed and the certificate will be issued under the Digicert root. For the other impacted application, we will keep the underscore but migrate the certificate to our internal CA. In both case, modification to the applications and infrastructures are required and consequently have more risks than a usual certificate renewal. Because of that we must test the change in lower environment and follow a strict change management process that requires validation in lower environment before getting approval to implement in production.
For that reason, we would appreciate if the certificates with underscore were not revoked until February 28, 2019."
Updated•7 years ago
|
Comment 2•7 years ago
|
||
The original report said:
- January 26, 2018 - Proposal on when all certs will be revoked.
And the modified now says
For that reason, we would appreciate if the certificates with underscore were not revoked until February 28, 2019.
I'm curious what lead to the change in evaluation of timelines and risk?
| Assignee | ||
Comment 3•7 years ago
|
||
Hi Ryan, The customer was aggressively targeting to get all certs replaced by this January month end. They asked for a sufficient period of time to ensure they can address any issues during the change process if a rollback is required. They want to ensure a successful implementation before the February 28, 2019 date.
Comment 4•7 years ago
|
||
Brenda: Can you confirm whether an incident occurred and ensure that all of the details of affected certs are accurate?
| Assignee | ||
Comment 5•7 years ago
|
||
I can confirm that an incident has occurred and the details provided are accurate to the best of our knowledge. Our planned extension to revoke the remaining certificates (listed above) is 28-February-2019. We will provide periodic updates as progress is made.
| Assignee | ||
Comment 6•7 years ago
|
||
Update: All remaining underscore certs, as noted above, have either expired or were revoked.
Updated•7 years ago
|
Updated•3 years ago
|
Updated•3 years ago
|
Description
•