Cybertrust Japan: Root CRLs exceed maximum validity period by one second
Cybertrust Japan reported a compliance issue affecting root CRLs: four current root CRLs had a validity period of 365 days plus one second. The CA stated this did not comply with BR section 4.9.7, which requires that the nextUpdate field must not be more than twelve months beyond the thisUpdate field. Cybertrust Japan said it identified the problem on October 20, 2021 by reviewing other CA incident reports, and it noted that certificate issuance was not stopped because the issue did not result in misissuance of certificates. The CA issued corrected CRLs on October 22, and it posted both a preliminary incident report (October 22) and a full incident report (October 26). The thread also states that impact was limited to root CRLs and that subscriber certificates were not impacted. The bug was resolved with resolution set to FIXED.
- Cybertrust Japan identified that four root CRLs had nextUpdate values exceeding the BR 4.9.7 limit by one second.
- Cybertrust Japan issued corrected root CRLs to remediate the CRL validity period issue.
- Cybertrust Japan completed investigation and posted the full incident report.
- SECOM Trust Systems CO., LTD. — Posted a preliminary incident report stating that four root CRLs had validity of 365 days plus one second and that corrected CRLs were being re-issued on October 22.
- SECOM Trust Systems CO., LTD. — Provided a full incident report describing how the issue was discovered, the timeline of actions, remediation steps (corrected CRLs), and stated that subscriber certificates were not impacted.
- SECOM Trust Systems CO., LTD. — Noted that Cybertrust Japan would monitor the bug for community questions.
- Mozilla representative — Asked whether there was any reason the bug could not be closed.
- Mozilla representative — Indicated Mozilla would close the bug sometime next week.