Apple: CRL issuance frequency deviates from CPS in some cases
Apple CA reported that, during a review of its validation services related to Bug 1771398, an engineer identified that CRL issuance frequency for Apple’s public TLS and S/MIME CAs was configured for 24 hours but in some cases occurred at a 37.5 hour interval, deviating from the Apple Public CPS. Apple stated this was an incident because its stated practice in the Apple Public CPS (section 4.9.7) is every 24 hours. Apple investigated the root cause, attempted to reproduce the issue in a non-production environment, and opened a support ticket with its software vendor. Apple determined it could not reproduce the issue in non-production and applied a fix on 2022-06-02 by creating an additional CRL worker with fewer CAs. Apple confirmed on 2022-06-03 that CRL issuance frequency returned to a 24 hour interval and added increased logging and monitoring, including alerts if CRLs are not generated every 24 hours. Apple later posted an updated Apple Public CPS (v5.7) with changes to sections 4.9.7 and 4.9.8 and stated there were no outstanding tasks, asking to close the incident; Mozilla indicated it would close the bug around 6 July 2022.
- Effective date of Apple Public CPS version 5.0, which stated CRL issuance frequency is every 24 hours.
- Apple identified that CRL issuance frequency for public TLS and S/MIME CAs sometimes occurred at a 37.5 hour interval instead of the configured 24 hours.
- Apple applied a fix by creating an additional CRL worker with fewer CAs.
- Apple confirmed CRL issuance frequency was occurring at a 24 hour interval and filed the Bugzilla incident report.
- Apple posted an updated Apple Public CPS (v5.7) with changes to sections 4.9.7 and 4.9.8.
- Apple representative — Apple reported that CRL issuance frequency was configured for 24 hours but sometimes occurred at a 37.5 hour interval, and stated the issue had been resolved while promising a full report by June 17, 2022.
- Apple representative — Apple provided a detailed incident timeline, stated certificate issuance was not affected, described the remediation (additional CRL worker), and noted added logging/monitoring and CPS updates.
- Internet Security Research Group — Let’s Encrypt commented that the bug highlights risk in using a hard interval in the CPS and asked whether Apple would review and update the CPS wording.
- Apple representative — Apple responded that it was reviewing and updating the Apple Public CPS and would post changes to sections 4.9.7 and 4.9.8.
- Apple representative — Apple stated it posted Apple Public CPS v5.7 with the updated sections 4.9.7 and 4.9.8 to its public repository.
- Apple representative — Apple said there were no outstanding tasks and asked whether the incident could be closed.
- Mozilla representative — Mozilla indicated it would close the bug on or about 6 July 2022 unless further discussion was needed.