SSL.com: Expired CRLs
This case reports that, while processing revoked intermediate certificates for OneCRL (referenced as Bug #1550537#c1), SSL.com found several CRLs that were expired. The CRLs listed include SSL.com Enterprise intermediate CRLs and InterCloud Ventures intermediate CRLs, each showing a last update date of Apr 5 2019 and a next update date of Apr 12 2019. Chris Kemmerer responded that the issuing CAs were previously revoked and therefore could not issue new CRLs. Kathleen Wilson closed the bug as INVALID, stating that the parent certificate was revoked, which prevented the CA from creating new CRLs. She also noted that CCADB has a revocation status option for “Parent Cert Revoked,” and that she did not notice it applied in this situation. She indicated that because the current batch of additions to OneCRL was large and already verified, it would continue as-is.
- SSL.com identified multiple expired CRLs while processing revoked intermediate certificates for OneCRL.
- SSL.com stated the issuing CAs were already revoked and could not issue new CRLs.
- SSL.com closed the bug as invalid due to the parent certificate being revoked.
- Community commenter — Kathleen reported that several CRLs for revoked intermediates were expired while processing OneCRL additions.
- Community commenter — Chris said all listed issuing CAs were previously revoked and therefore could not issue new CRLs.
- Community commenter — Kathleen closed the bug as INVALID, explaining the parent cert was revoked and the CA could not create new CRLs, and said the OneCRL batch would continue as-is.