Closed Bug 2016475 Opened 7 months ago Closed 3 months ago

Firmaprofesional: Delayed revocation disclosure of TLS Subordinate CA certificate Secure Web 2024 in CCADB

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: ext-antoni.camon, Assigned: ext-antoni.camon)

Details

(Whiteboard: [ca-compliance] [disclosure-failure])

Preliminary Incident Report

Summary

  • Incident description:
    The TLS Subordinate CA certificate “Secure Web 2024” was revoked; however, its revocation was not disclosed in the CCADB within the timeframe required by Section 3.2 of the CCADB Policy.

  • Relevant policies:
    CCADB Policy Section 3.2 – "revocation of all subordinate CA certificates capable of validating to a certificate included in a Root Store or associated with a CCADB Root Inclusion Request within 7 calendar days of revocation.”

  • Source of incident disclosure:
    Third Party Reported (Chrome Root Program)

Assignee: nobody → ext-antoni.camon
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true
Whiteboard: [ca-compliance] [disclosure-failure]

Firmaprofesional: Delayed revocation disclosure of TLS Subordinate CA certificate “Secure Web 2024” in CCADB

Full Incident Report

Summary

  • CA Owner CCADB unique ID: A000006

  • Incident description:
    During remediation of Bugzilla #2009941, Firmaprofesional revoked the affected TLS Subordinate CA certificate “Secure Web 2024”, but the revocation was not disclosed in CCADB within the 7-calendar-day timeframe required by CCADB Policy Section 3.2.

  • Timeline summary:

    • Non-compliance start date: 2026-01-30 12:00 UTC (7 days after SubCA revocation timestamp used in Bug #2009941)
    • Non-compliance identified date: 2026-02-04 UTC (third-party report)
    • Non-compliance end date: 2026-02-04 UTC (CCADB disclosure corrected during incident handling)
  • Relevant policies:

    • CCADB Policy, Section 3.2
      • Disclosure of revocation of subordinate CA certificates within 7 calendar days.
  • Source of incident disclosure:
    Third Party Reported (Chrome Root Program).


Impact

  • Total number of certificates: 1 TLS Subordinate CA certificate affected by delayed CCADB disclosure.

  • Total number of "remaining valid" certificates: N/A

  • Affected certificate types: TLS Subordinate CA

  • Incident heuristic: Single disclosure record associated with the SubCA from Bug #2009941.

  • Was issuance stopped in response to this incident, and why or why not?: No issuance stop was required for this disclosure-specific bug.

  • Analysis: N/A


Timeline

  • 2026-01-23 11:00 UTC – Revocation of the affected TLS Subordinate CA completed.
  • 2026-01-30 11:00 UTC – CCADB 7-day disclosure deadline elapsed.
  • 2026-02-04 17:15 UTC – Chrome Root Program reports Policy Non-compliance via mail.
  • 2026-02-04 19:00 UTC – CCADB revocation disclosed.

Related Incidents

Bug Date Description
N/A N/A No related incidents identified

Root Cause Analysis

Contributing Factor #1: Missing hard control linking revocation completion to CCADB disclosure deadline

  • Description:
    At the time of the incident, the Subordinate CA revocation process did not include a mandatory control ensuring that CCADB disclosure under Section 3.2 was formally tracked, assigned to an owner, and validated within the required 7-day timeframe.
    Although the revocation was completed and the incident was publicly documented in Bugzilla, CCADB disclosure was not embedded as a formal revocation-closure requirement with explicit deadline tracking. As a result, completion of the technical revocation and public incident communication did not inherently ensure completion of the corresponding CCADB disclosure obligation.

  • Timeline:
    CCADB disclosure was not embedded in the revocation workflow, no deadline tracking was triggered when the revocation was completed. As a result, the 7-day disclosure requirement elapsed on 2026-01-30 without the required CCADB update.
    The control gap was identified on 2026-02-04 following third-party notification.

  • Detection:
    The missing disclosure was identified following third-party notification (Chrome Root Program), after which internal verification confirmed that the CCADB Section 3.2 disclosure had not been completed within the required timeframe.

  • Interaction with other factors:
    Because CCADB disclosure was not embedded as a mandatory revocation-closure control with deadline enforcement, completion of other incident management activities did not automatically guarantee compliance with the 7-day CCADB reporting requirement.


Lessons Learned

  • What went well:

    • The revocation itself was completed.
    • The disclosure gap was acknowledged and documented transparently.
  • What didn’t go well:

    • CCADB disclosure obligations were not enforced as a formal closure gate.
  • Where we got lucky:

    • The issue affected a single SubCA disclosure record and was quickly correctable once identified.
  • Additional:
    Future incident closure must include both technical state and external registry/disclosure state.


Action Items

Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status
Update SubCA revocation procedure to formally require CCADB Section 3.2 disclosure with assigned owner and documented deadline (T+7 days) Prevent Root Cause Updated procedure approved, documented, and communicated internally 2026-03-06 Planned
Add mandatory “CCADB disclosure confirmed” validation step before revocation case closure Prevent Root Cause No SubCA revocation case can be closed without documented evidence of CCADB disclosure 2026-03-06 Planned

Appendix

(In reply to ext-antoni.camon from comment #1)

  • Timeline summary:
    • Non-compliance start date: 2026-01-30 12:00 UTC (7 days after SubCA revocation timestamp used in Bug #2009941)
    • Non-compliance identified date: 2026-02-04 UTC (third-party report)
    • Non-compliance end date: 2026-02-04 UTC (CCADB disclosure corrected during incident handling)

Timeline

  • 2026-01-23 11:00 UTC – Revocation of the affected TLS Subordinate CA completed.
  • 2026-01-30 11:00 UTC – CCADB 7-day disclosure deadline elapsed.
  • 2026-02-04 17:15 UTC – Chrome Root Program reports Policy Non-compliance via mail.
  • 2026-02-04 19:00 UTC – CCADB revocation disclosed.

Your timeline is missing quite a lot of detail. Notably you're mentioning a Certificate Problem Report from Chrome Root Program on 2026-02-04, there's a preliminary incident here on 2026-02-12, and now the final report 2026-02-25.

We're either having missed handling the CPR within 24h, failing to issue the Preliminary Report with 72h, and/or failing to publish the full incident report within 14 days of becoming aware of the problem. Your non-compliance identified date implies it was 2026-02-04 that you became fully aware of the issue...

Thank you for the clarification. We are reviewing the timeline and reporting milestones associated with this incident to ensure they are described accurately and completely in the bug record.

Separately, the two Action Items currently defined in this report have been completed. The updated Action Items table is provided below.

Updated Action Items

Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status
Update SubCA revocation procedure to formally require CCADB Section 3.2 disclosure with assigned owner and documented deadline (T+7 days) Prevent Root Cause Updated procedure approved, documented, and communicated internally 2026-03-06 Completed
Add mandatory “CCADB disclosure confirmed” validation step before revocation case closure Prevent Root Cause No SubCA revocation case can be closed without documented evidence of CCADB disclosure 2026-03-06 Completed

Despite prior warnings in Comment 2 no updates have arrived and based on the information provided:
Preliminary Report was not issued before 72h - a separate incident to be raised.
Final Incident Report was not issued before 14 days - a separate incident to be raised.

Please note that following the CCADB Incident Reporting Guidelines updates should be provided weekly, unless a 'next update' date has been set in advance. That is a separate incident to be raised.

When are reports updated?

CA Owners SHOULD respond promptly to comments and questions, and MUST respond within 7 days, even if only to acknowledge the request and provide a timeline for a full response.

If you believe this incident is resolved please submit a closure report.

Thank you for the clarification.
We agree that, based on the dates reflected in this record, the delayed publication of the Preliminary Incident Report and the delayed publication of the Full Incident Report should be tracked separately from the disclosure-specific issue described in this bug.
This bug remains focused on the delayed CCADB disclosure under CCADB Policy Section 3.2. We are preparing separate incident tracking for the reporting-timeliness issues associated with this case, and we will cross-reference it here once published.
We also acknowledge the point regarding missed weekly updates and response timeliness under the Incident Reporting Guidelines, and we are reviewing that aspect for appropriate follow-up.

For clarity, the separate incident relating to delayed initial incident reporting (72-hour preliminary report / 14-day full report timing) is being tracked in bug 2025536.

The separate incident relating to delayed weekly updates / response timeliness on open incident reports is being tracked in bug 2025538.

Report Closure Summary

  • Incident description: During remediation of Bugzilla #2009941, Firmaprofesional revoked the affected TLS Subordinate CA certificate "Secure Web 2024", but did not disclose that revocation in CCADB within the 7-calendar-day timeframe required by CCADB Policy Section 3.2.
  • Incident Root Cause(s): The incident was caused by the absence of a hard control linking completion of Subordinate CA revocation to CCADB disclosure, including missing owner assignment, missing deadline tracking, and the lack of a mandatory validation step before revocation case closure.
  • Remediation description: Firmaprofesional completed the remediation actions described in this report by updating the SubCA revocation procedure to require CCADB Section 3.2 disclosure with assigned ownership and documented deadline tracking, and by adding a mandatory "CCADB disclosure confirmed" validation step before any revocation case can be considered closed.
  • Commitment summary: Beyond the completed Action Items, Firmaprofesional will maintain CCADB disclosure verification as a standing closure condition for future Subordinate CA revocation cases, including continued owner assignment, deadline tracking, and final validation that external disclosure obligations have been completed before case closure.

All Action Items disclosed in this report have been completed as described, and we request its closure.

There is no material change since our closure request.

This incident remains pending review. The separate incidents relating to delayed initial incident reporting and delayed weekly updates / response timeliness continue to be tracked in bugs 2025536 and 2025538 respectively.

We will provide the next update by 2026-04-14, or earlier if there is a material change.

There is no material change since our previous update.

This incident remains pending review. The separate incidents relating to delayed initial incident reporting and delayed weekly updates / response timeliness continue to be tracked in bugs 2025536 and 2025538 respectively.

We will provide the next update by 2026-04-21, or earlier if there is a material change.

There is no material change since our previous update.

This incident remains pending review. The separate incidents relating to delayed initial incident reporting and delayed weekly updates / response timeliness continue to be tracked in bugs 2025536 and 2025538 respectively.

We will provide the next update by 2026-04-28, or earlier if there is a material change.

There is no material change since our previous update.

This incident remains pending review.

We will provide the next update by 2026-05-05, or earlier if there is a material change.

There is no material change since our previous update.

This incident remains pending review.

We will provide the next update by 2026-05-12, or earlier if there is a material change.

Flags: needinfo?(incident-reporting)

This is a final call for comments or questions on this Incident Report.

Otherwise, it will be closed on approximately 2026-05-15.

Flags: needinfo?(incident-reporting)
Whiteboard: [ca-compliance] [disclosure-failure] → [close on 2026-05-15] [ca-compliance] [disclosure-failure]
Status: ASSIGNED → RESOLVED
Closed: 3 months ago
Resolution: --- → FIXED
Whiteboard: [close on 2026-05-15] [ca-compliance] [disclosure-failure] → [ca-compliance] [disclosure-failure]
You need to log in before you can comment on or make changes to this bug.