SSL.com: CRL not found for SSL.com-Enterprise-Intermediate-EV-RSA-4096-R1.crl
The bug was opened after Kathleen Wilson encountered a “CRL file not found” condition while processing revoked intermediate certificate records in CCADB. The CRL URL listed in the record was http://crls.ssl.com/SSL.com-Enterprise-Intermediate-EV-RSA-4096-R1.crl, but the CRL was available at a different URL. Chris Kemmerer reported the issue was resolved on May 6, 2019, and that the CRL had been updated to include the entry for the revoked intermediate certificate. Kathleen Wilson noted that an incident report was needed because Mozilla Baseline Requirements section 4.9.7 requires CRL updates within 24 hours after revoking a subordinate CA certificate. In the later incident report text, SSL.com stated it had not stopped issuing certificates and that the problem did not affect certificate issuance, but rather CRL publishing for a revoked CA. The bug is marked RESOLVED with resolution FIXED, and a later comment indicated remediation was complete.
- SSL.com created a CA compliance bug ticket after discovering a CRL issue while processing revoked intermediate certificate records.
- SSL.com updated CRL publishing so the revoked intermediate certificate entry was included and the CRL was available from the expected location.
- SSL.com provided an incident report describing how the CRL was published to the wrong URL and the remediation steps taken.
- A participant stated that remediation appeared complete.
- Community commenter — Reported that CCADB processing hit “CRL file not found” for the revoked intermediate certificate and listed the CRL URL(s) and revocation date.
- Community commenter — Said the issue was resolved as of 10:57am CST May 6, 2019, and that a report would be uploaded to the bug.
- Community commenter — Set “needs-info” pending the incident report.
- Community commenter — Confirmed the CRL was updated to include the revoked intermediate certificate entry and cited Baseline Requirements 4.9.7 as the reason an incident report was needed.
- SSL.com — Posted an incident report describing how SSL.com became aware of the problem, the timeline, the wrong CRL URL location, and remediation steps.
- Community commenter — Asked Wayne if there were any further questions.
- Fastly representative — Noted it appeared all questions were answered and remediation was complete.