IdenTrust: CRL Potential Publication Delay due to Cache
IdenTrust reported that, following an internal self-audit on 2022-06-13, it suspected its CRLs might not be published within one hour of authenticating a revocation request as required by Section 4.9.8 of its TrustID CPS. The CA stated that a routine software change control implemented on 2022-05-21 introduced publishing and configuration changes that could result in CRLs being published more than 60 minutes after revocation request authentication. After further investigation, IdenTrust found that up to 46 authenticated revocation requests may have had their corresponding CRLs published more than 60 minutes after authentication, which it said would violate the CPS requirement. The CA indicated that the issue was related to a caching misconfiguration in CRL load balancers, where production caching parameters did not match pre-production. IdenTrust corrected the load balancer configuration in production and stated that CRLs are no longer cached in load balancers to prevent recurrence. The CA later confirmed there were no pending actions and considered the issue resolved, and Mozilla indicated it would close the bug if no further questions arose. The bug is marked RESOLVED with resolution FIXED.
- IdenTrust initiated and completed a routine software change control that could affect CRL publishing and configuration.
- IdenTrust internal audit identified a potential CRL caching misconfiguration and suspected delayed CRL publication.
- IdenTrust corrected production load balancer caching configuration and identified affected CRLs for up to 46 revoked TLS certificates.
- IdenTrust confirmed there were no pending actions and considered the issue resolved.
- IdenTrust Services, LLC — IdenTrust created the bug after an internal self-audit, describing a suspected CRL publication delay due to CRL load balancer caching and stating that up to 46 authenticated revocation requests may have been affected.
- IdenTrust Services, LLC — IdenTrust confirmed there were no pending actions and considered the issue resolved.
- Mozilla representative — Mozilla stated it would close the bug on 8-July-2022 if there were no questions or issues to discuss.