Skip to content

The Expired Certificate That Took Millions Offline

An expired certificate in Ericsson core-network software disrupted operators across 11 countries. A shared dependency carried a scheduled failure.

Episode 123 minute read

One dependency across many networks

On December 6, 2018, an Ericsson software problem disrupted mobile networks including O2 in the UK and SoftBank in Japan. Ericsson identified an expired certificate in two versions of its SGSN-MME core-network software. SoftBank said it had been informed of simultaneous failures across 11 countries using the same supplier's equipment.

A date in a deployed dependency

A certificate includes a validity period. Systems that depend on it need a working response before that period ends. The operational risk is therefore present long before the expiry date: deployment is not complete unless the dependency has an owner and a renewal or replacement plan.

Ericsson's initial statement identified the expired certificate as the main issue. That supports the shared-dependency lesson, but it is not a detailed public trace of every authentication exchange inside the affected software. The episode's identity-card comparison explains the general concept of expiry, rather than documenting a complete packet-level reconstruction.

Recovery was different for each operator

SoftBank recorded an outage from 1:39 p.m. to 6:04 p.m. Japan time and said it restored service by reverting its packet-switching systems to older software. The duration of the incident was not identical across all affected networks.

O2's disruption extended into the following day. Potential Ericsson compensation was reported; the cited report does not establish a final settlement amount. Recovery timing and commercial consequences should not be treated as one uniform global figure.

What to own before expiry

Maintain an inventory of certificates and other dated dependencies, including those embedded in supplier software. Assign ownership, alert well before expiry and test the renewal path. Monitoring should cover the dependency's effect on service, as well as whether a certificate file exists.

A shared component can make a scheduled failure arrive across many installations together. Ask suppliers how expiry is monitored and how replacements are distributed, and maintain a tested rollback or recovery procedure. A date printed in a dependency is an operational input that needs the same attention as a configuration change.

Sources

3 sources

Every figure in this article traces to one of the following: the same record the episode cites.

01Zof Console

One surface for posture, operations, and what needs attention next.

The authenticated home that engineering, QA, and SRE teams open every day: quality posture, in-flight runs, coverage by module, and what needs attention next.

OPERATIONAL KPIs

  • Runs
  • Coverage
  • Risk

Live across every environment you ship to.

WORK SPINE

  • Specs
  • Tests
  • Schedules

From specification to scheduled regression.

GUARDRAILS

  • RBAC
  • SSO
  • audit

Every action attributable to a named human.

LIVE/console
Zof AI home command center showing 12 runs at 94% pass, 3 open critical issues, 84% coverage, four module traceability bars, the specification pipeline, upcoming schedules, and recommended next actions with an active-runs sidebar.
Console home · Checkout Service · Staging · captured live from the product.
The Expired Certificate That Took Millions Offline | Zof AI