← Apple Inc. cases
Bugzilla #1772644
Technical Compliance
Apple: CRL issuance frequency deviates from CPS in some cases
RESOLVED
FIXED
Apple Inc.
AI Summary
Apple identified that the Certificate Revocation List (CRL) issuance frequency for its public TLS CAs was configured for 24 hours but was occurring at a 37.5 hour interval in some cases, which deviated from their stated practice in the Apple Public Certificate Policy Statement (CPS). The issue was resolved by creating an additional CRL worker, ensuring compliance with the 24-hour issuance frequency. Apple is also reviewing and updating the CPS to address hard interval settings.
Chronology
- Issue identified during review of validation services
- Fix applied to ensure CRL issuance frequency met CPS requirements
- Updated version of the Apple Public CPS posted
Participants
certification_authority@apple.com
aaron@letsencrypt.org
bwilson@mozilla.com
External References
Similar Local Cases
GDCA: CRL validity period exceeds allowed value by one second
Certainly: Root CRL validity period exceeds maximum by one second
Microsoft PKI Services: 3-Month Access Review Process Failure
Amazon Trust Services: CRL not DER-encoded
GlobalSign: CRL contains invalid signature algorithm
Microsoft PKI Services: Trusted Role Control Failure
GoDaddy: inconsistent CP/CPS disclosure
Certigna: Finding #3 ETSI Audit – Event log protection beyond seven years shall be improved