Izenpe: CRL and ARL exceed validity period value by one second
Izenpe reported that its CRL and Root certificate ARL validity periods exceeded the intended duration by one second, which it stated did not comply with BR 4.9.7. The CA said it discovered the issue after reviewing prior Bugzilla incidents and checking its ARL/CRL endpoints, noting a 365 days and 1 second lapse between issuing date and NextUpdate date for the Root ARL and similar behavior for CRLs that should last 10 days. Izenpe stated it tested a configuration change in a development environment to subtract 1 second and then updated its configuration when reissuing the ARL. It reported that it published a new ARL and that publishing new CRLs for intermediate certificates was planned for 2021-10-29. A later comment confirmed that the CRLs were published without the extra second duration. Mozilla indicated it would close the bug on 16-Feb-2022 unless there were questions, and the bug is resolved as FIXED.
- Izenpe identified that its ARL/CRL NextUpdate timing exceeded the intended validity duration by one second and began testing a configuration change.
- Izenpe published a new ARL and updated intermediate CRLs so they no longer included the extra one-second duration.
- Izenpe S.A. — Izenpe explained that its Root ARL and CRLs had a one-second lapse beyond the configured validity period, citing BR 4.9.7, and described testing and planned reissuance steps.
- Izenpe S.A. — Izenpe stated that the CRLs are now published without the extra second duration.
- Mozilla representative — Mozilla said it would close the bug on 16-Feb-2022 unless there were questions or issues to discuss.