← iTrusChina Co., Ltd. cases
Bugzilla #1712664 Certificate Problem Report

iTrusChina: verification errors for the roots' CRLs(ARL)

RESOLVED FIXED iTrusChina Co., Ltd.
AI Summary

iTrusChina identified a design bug in their offline CA's ARL system that caused signature verification failures for their roots' CRLs. The issue was first reported on May 21, 2021, and iTrusChina took immediate action, halting certificate issuance and troubleshooting the problem. They discovered that the ARL information was not correctly assembled before signing, leading to inconsistencies. The bug was fixed, and a new version of the CA system was deployed to ensure proper verification of newly issued ARLs and CRLs. The case has been resolved with the implementation of additional checks to prevent future occurrences.

Model: gpt-4o-mini Generated: 2026-06-13 21:11 UTC Confidence: 0.90
Chronology
  1. Issue reported in public discussion.
  2. iTrusChina began troubleshooting the issue.
  3. Bug identified and fixed in the CA system.
  4. Case resolved and bug marked as fixed.
Participants
vTrus_contact@itrus.cn ryan.sleevi@gmail.com bwilson@mozilla.com
External References
Similar Local Cases
#1719916 RESOLVED Certificate Problem Report Opened 2021-07-09 · Closed 2023-02-22 · 58% similar
SSL.com: Issuance of an EV TLS certificate with incorrect O Field Value
#1722089 RESOLVED Certificate Problem Report Opened 2021-07-23 · Closed 2023-02-22 · 58% similar
SSL.com: Issuance of 3 EV TLS certificates without 2-person validation of the organization information
#1659316 RESOLVED Certificate Problem Report Opened 2020-08-16 · Closed 2023-02-22 · 58% similar
Apple: EV Certificate Approver Authorization
#1610303 RESOLVED Certificate Problem Report Opened 2020-01-20 · Closed 2023-02-22 · 57% similar
D-TRUST: Issuance of non-conformant SSL certificate
#1639502 RESOLVED Certificate Problem Report Opened 2020-05-20 · Closed 2023-02-22 · 56% similar
Asseco DS / Certum: Incorrect OCSP response encoding
#1677234 RESOLVED Certificate Problem Report Opened 2020-11-13 · Closed 2023-02-22 · 56% similar
Apple: OCSP availability 2020-11-12
#1637093 RESOLVED Certificate Problem Report Opened 2020-05-11 · Closed 2023-02-22 · 55% similar
Multicert: AIA CA Issuer field pointing to PEM encoded cert
#1636141 RESOLVED Certificate Problem Report Opened 2020-05-07 · Closed 2023-02-22 · 55% similar
SwissSign: failure to provide a preliminary report within 24 hours

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action