← IdenTrust Services, LLC cases
Bugzilla #1775454
Certificate Problem Report
IdenTrust: CRL Potential Publication Delay due to Cache
RESOLVED
FIXED
IdenTrust Services, LLC
AI Summary
IdenTrust Services, LLC reported a potential delay in the publication of Certificate Revocation Lists (CRLs) due to a caching misconfiguration. An internal audit revealed that up to 46 revoked TLS certificates may not have had their corresponding CRLs published within the required one-hour timeframe. The issue arose after a software change control on May 21, 2022, which led to discrepancies between production and test environment configurations. IdenTrust has since corrected the configuration and confirmed that there are no pending actions, considering the issue resolved.
Chronology
- Initiated change control
- Internal audit suspected caching misconfiguration
- Confirmed issue resolved
Participants
IdenTrust
Mozilla
External References
Similar Local Cases
IdenTrust: Missing Revocation Reasons in CRL
IdenTrust: Expired CRLs
IdenTrust: Failure to provide OCSP responses for valid ICA certificates
IdenTrust: Expired ICAs CRLs
IdenTrust: Failure to Revoke Subscriber Certificates Within 5 days
IdenTrust: Pre-certificates without a final certificate showing OCSP error
IdenTrust: TLS self audit testing below 3%
IdenTrust: TLS ICA with User Notice in Policy Qualifier