CA/Responding To An Incident

< CA
Revision as of 15:04, 15 August 2017 by Gerv (talk | contribs) (Super-rough first notes)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Draft-template-image.png THIS PAGE IS A WORKING DRAFT Pencil-emoji U270F-gray.png
The page may be difficult to navigate, and some information on its subject might be incomplete and/or evolving rapidly.
If you have any questions or ideas, please add them as a new topic on the discussion page.
  • Were you aware of this issue before it was reported
  • Scanning your corpus of certs for others with the same issue
  • What processes should have prevented this, if any? Why did they fail?
  • What steps are you taking to make sure it doesn't happen again?

Take any issuing CA affected offline immediately

Post any updates as new threads, with a comment in the old thread referencing it. (Explain why)

Examples of Good Practice

Let's Encrypt Unicode Normalization Compliance Incident

In this case, the CA managed to diagnose, remediate and deploy the fix to production within 24 hours.

PKIOverheid Short Serial Number Incident

While the CA could have provided interim updates, and the final report was a little delayed, the contents of it were excellent.