Google Trust Services: CRL handling of expired certificates not fully compliant with RFC 5280 Section 3.3
Google Trust Services reported a compliance issue in its CRL generation system for GTS CA 1O1. During an internal review and assessment on August 16, 2019, it was discovered that the CRL generation service did not include CRL entries of expired certificates because the periodic job only considered certificates with valid lifetimes, which the CA stated does not conform to RFC 5280 Section 3.3. The CA said it filed a bug to fix the issue and developed a patch that populated expired certificates in the CRL for 7 days after expiration so they appear in at least one regularly issued CRL update, and added automated testing to ensure revoked certificates are kept in the CRL. The CA reported that the patch was developed, tested, reviewed, and landed by August 19, 2019, and that remediation was completed with a staged rollout to production expected to finish by September 3, 2019 (slightly extended). In a follow-up update, the CA stated that the push to fully address the issue was completed globally shortly before 16:00 UTC on 2019-09-02 and that only two specific certificates were affected, providing crt.sh links. The bug was later marked as resolved with the CA stating remediation was complete and that no further work or information was outstanding.
- During internal review, Google Trust Services discovered its CRL generation did not include expired-certificate entries in regularly scheduled CRLs as required by RFC 5280 Section 3.3.
- A patch to include expired certificates in CRLs for 7 days after expiration was developed, tested, reviewed, and landed in the codebase.
- Google Trust Services completed the global rollout of the remediation patch to fully address the CRL handling issue.
- Fastly representative — Wayne Thayer posted an incident report describing the discovery, the non-compliant CRL generation behavior, and the CA’s remediation timeline and actions.
- Fastly representative — Wayne Thayer posted a follow-up stating the global remediation push was completed shortly before 16:00 UTC on 2019-09-02 and that only two certificates were affected, with crt.sh links.
- Fastly representative — Wayne Thayer stated that it appeared all questions had been answered and remediation was complete.