← iTrusChina Co., Ltd. cases
Bugzilla #1712664
Ca Certificate Compliance
iTrusChina: verification errors for the roots' CRLs(ARL)
RESOLVED
FIXED
iTrusChina Co., Ltd.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
iTrusChina Co., Ltd. reported a design bug in their offline CA's ARL system that led to verification errors for their root certificates' CRLs. The issue was first identified by Andrew Ayer on May 21, 2021, and iTrusChina acknowledged the problem on May 24, 2021. They halted certificate issuance during the troubleshooting process, which involved identifying and fixing the bug in the ARL signature process. The CA implemented a new feature to automatically verify the signatures of newly issued ARLs and CRLs. The issue was resolved, and the new version of the CA system was deployed on May 25, 2021.
Chronology
- Issue reported by Andrew Ayer regarding verification errors.
- iTrusChina acknowledged the issue and began troubleshooting.
- New version of the CA system was deployed to resolve the issue.
Thread Activity
- iTrusChina Co., Ltd. — Reported a design bug causing signature verification failures.
- Community commenter — Inquired about the seriousness of the security issue.
- iTrusChina Co., Ltd. — Provided detailed steps of the ARL generation process.
- iTrusChina Co., Ltd. — Requested to resolve the bug as fixed after completing testing.
Participants
iTrusChina Co., Ltd.
Community commenter
Mozilla representative
External References
Similar Local Cases
iTrusChina: Finding in Routine WebTrust Audit - Domain validation records without the TLS BR version
iTrusChina: CRL Reason Codes
DigiCert: Issuance of Cert with Compromised Key
Sectigo: invalid subject:organizationalUnitName on DV certificates
NetLock: Replacement of enduser certificates after the EVGL 1.7.4 self-audit
Microsoft PKI Services: Malformed ICAs (Key Usage Malformed)
e-commerce monitoring GmbH: CN domain not in SAN
D-TRUST: Issuance of non-conformant SSL certificate