Would it be fair during that time if I asked you to hold your PRs, bug tickets and work in general because we're on paid leave?
On-call rotation exists for those reasons. Otherwise, all countries would need to respect all other countries holidays.
In fact, we're not even aware of most US holidays. It is likely to be a coincidence.
There are whole startups designed to solve this, like PagerDuty.
I am now very curious to understand where your question comes from. There must be some misunderstanding here. You never went on-call or seen a friend do it?
Red herring [1].
OP said it’s malicious or incompetent to release this on a U.S. holiday weekend. You asked if similar consideration would be given to Brazil. Multiple people chimed in that it would. You’re now pivoting to on-call capacity.
Any amount of on-call capacity can be saturated. That’s why competent multinationals avoid releasing while markets they’re likely to impact are sleeping or drunk. This is a high-level scheduling operation, however, so it’s reasonable for those lower in the organisation to be unaware why an update is being pushed next Tuesday instead of this.
In fact, your example is perfect. We're not talking about business. CAs are different.
In security and infrastructure, there's always someone working on holidays. The larger the organization, higher are the chances that some kind of rotation exists.
Rotations exist, specially in large organizations, or when there's shared responsibility.
Now we're talking nonsense about "you said, he said", this conversation makes no sense. I am much less invested in this than you think.
Straw man [1]. Nobody claimed otherwise.
Rotation or always-on isn’t a substitute for being aware of your customers. Good culture permeate this throughout the organisation. Competent ones have someone at the top ensuring controls are followed.
You’re not. Someone above you should be. Otherwise that’s incompetence.
What I’m attempting to refer to, is that _if_ this was done with malicious intent, then maybe the hope was that doing it during a holiday would reduce response time or allow it to fly under the radar. Of course, as you say, just because it was a holiday does not inherently mean it’s malicious, it has plausible deniability.
I don't know if there's a rotation or another system. I think there are probably multiple across different parties responsible for maintaining CA trust.