← Certainly LLC cases
Bugzilla #1732745
Technical Compliance
Certainly: Root CRL validity period exceeds maximum by one second
RESOLVED
FIXED
Certainly LLC
AI Summary
Certainly LLC identified a compliance issue with their root Certificate Revocation Lists (CRLs) during a routine review. The CRLs were found to have a validity period that exceeded the maximum allowed by the Baseline Requirements, specifically by one second. Although no certificates were misissued, the company initiated an incident management process and has since published updated CRLs that comply with the requirements. All remediation steps have been completed, and the issue has been resolved.
Chronology
- Compliance issue identified during routine review
- Full incident report posted
- Updated CRLs published with corrected validity period
Participants
Wayne Thayer
bwilson@mozilla.com
External References
Similar Local Cases
Certainly: CRL Issuing Distribution Point Mismatch in CCADB
GDCA: CRL validity period exceeds allowed value by one second
Entrust: Non-BR-Compliant OCSP Responder
Amazon Trust Services: CRL not DER-encoded
Microsoft PKI Services: 3-Month Access Review Process Failure
Consorci AOC: Non-BR-Compliant OCSP Responders
GlobalSign: CRL contains invalid signature algorithm
Microsoft PKI Services: Trusted Role Control Failure