The Expired Certificate That Took Millions Offline
An expired certificate in Ericsson core-network software disrupted operators across 11 countries. A shared dependency carried a scheduled failure.
One dependency across many networks
On December 6, 2018, an Ericsson software problem disrupted mobile networks including O2 in the UK and SoftBank in Japan. Ericsson identified an expired certificate in two versions of its SGSN-MME core-network software. SoftBank said it had been informed of simultaneous failures across 11 countries using the same supplier's equipment.
A date in a deployed dependency
A certificate includes a validity period. Systems that depend on it need a working response before that period ends. The operational risk is therefore present long before the expiry date: deployment is not complete unless the dependency has an owner and a renewal or replacement plan.
Ericsson's initial statement identified the expired certificate as the main issue. That supports the shared-dependency lesson, but it is not a detailed public trace of every authentication exchange inside the affected software. The episode's identity-card comparison explains the general concept of expiry, rather than documenting a complete packet-level reconstruction.
Recovery was different for each operator
SoftBank recorded an outage from 1:39 p.m. to 6:04 p.m. Japan time and said it restored service by reverting its packet-switching systems to older software. The duration of the incident was not identical across all affected networks.
O2's disruption extended into the following day. Potential Ericsson compensation was reported; the cited report does not establish a final settlement amount. Recovery timing and commercial consequences should not be treated as one uniform global figure.
What to own before expiry
Maintain an inventory of certificates and other dated dependencies, including those embedded in supplier software. Assign ownership, alert well before expiry and test the renewal path. Monitoring should cover the dependency's effect on service, as well as whether a certificate file exists.
A shared component can make a scheduled failure arrive across many installations together. Ask suppliers how expiry is monitored and how replacements are distributed, and maintain a tested rollback or recovery procedure. A date printed in a dependency is an operational input that needs the same attention as a configuration change.
Sources
3 sources
Every figure in this article traces to one of the following: the same record the episode cites.
Apology for Mobile Communication Service Troubles
SoftBank Corp.2018
