← IdenTrust Services, LLC cases
Bugzilla #1709192 Incident

IdenTrust: Unavailable CRL for IdenTrust ‘DST Root CA X3’

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

IdenTrust reported an incident regarding the unavailability of the Certificate Revocation List (CRL) for its ‘DST Root CA X3’ on April 30, 2021. The CA discovered the issue through internal monitoring, which indicated that the CRL had expired, potentially affecting customers' ability to retrieve CRL information. The problem was resolved on the same day, and IdenTrust committed to posting a complete incident report by May 14, 2021. The report detailed the timeline of events, corrective actions taken, and future preventive measures, including enhanced monitoring and alerting systems. The issue was marked as resolved, and IdenTrust has since implemented additional monitoring to prevent recurrence.

Model: gpt-4o-mini Generated: 2026-06-13 21:13 UTC Revised: 2026-06-16 19:18 UTC Confidence: 0.85 18 comments
Chronology
  1. CRL for ‘DST Root CA X3’ became unavailable due to expiration.
  2. IdenTrust submitted a complete incident report.
  3. IdenTrust enhanced monitoring for CRLs.
Thread Activity
  1. IdenTrust Services, LLC — IdenTrust reported the CRL for ‘DST Root CA X3’ was unavailable on April 30, 2021.
  2. IdenTrust Services, LLC — IdenTrust provided a complete incident report detailing the issue and corrective actions.
  3. IdenTrust Services, LLC — IdenTrust confirmed that monitoring for expired CRLs has been enhanced.
  4. IdenTrust Services, LLC — IdenTrust clarified the specifics of its monitoring for externally published CRLs.
Participants
IdenTrust Services, LLC Community commenter Mozilla representative Thisisntrocket representative
External References
Similar Local Cases
#1753287 RESOLVED Incident Opened 2022-02-02 · Closed 2024-07-08 · 100% similar
IdenTrust: Validation Source for EV Certificates not Publicly Disclosed
#1905446 RESOLVED Incident Opened 2024-06-28 · Closed 2024-12-09 · 96% similar
IdenTrust: Unauthorized OCSP response on a Timestamp certificate
#1900492 RESOLVED Incident Opened 2024-06-03 · Closed 2026-06-10 · 95% similar
IdenTrust: Invalid OrganizationIdentifier in S/MIME certificates
#1838315 RESOLVED Ca Security Vulnerability Incident Opened 2023-06-13 · Closed 2023-10-12 · 94% similar
IdenTrust: Certificate with missing details flagged by OCSP Watch
#2014610 RESOLVED Self Reported Incident Incident Opened 2026-02-05 · Closed 2026-04-11 · 88% similar
IdenTrust: Root OCSP Signer certificate mis-issuance
#2016585 RESOLVED Self Reported Incident Incident Opened 2026-02-12 · Closed 2026-06-15 · 88% similar
IdenTrust: Test Certificates from cross-signed roots not disclosed in CT Logs
#2014590 RESOLVED Self Reported Incident Incident Opened 2026-02-04 · Closed 2026-04-23 · 87% similar
IdenTrust: Unauthorized OCSP responses for cross-signed roots
#2025596 RESOLVED Self Reported Incident Incident Opened 2026-03-23 · Closed 2026-05-18 · 87% similar
IdenTrust: Delay in updating a Bugzilla ticket Bug 2014610 - Next update

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action