IdenTrust: Intermittent issuance/validation failures and website outage due to OCSP/CRL unavailability
IdenTrust reported a self-discovered incident on July 1, 2022, when unusually high traffic to identrust.com caused intermittent success of certificate issuance and OCSP validation. The incident led to CA/B Baseline Requirements and CPS violations, including OCSP servers not consistently responding to OCSP requests within 10 seconds, CRLs being generated but not retrievable by customers, and a lack of continuous ability to accept and respond to revocation requests. IdenTrust stated it became aware of the problem via its monitoring and alerting systems, which triggered at 11:03 AM MDT and initiated triage calls with relevant third-party vendors. During restoration efforts, IdenTrust later performed a configuration change in its CDN caching settings that inadvertently prevented access to CRLs, which was reported for certain issuance customers on July 2. IdenTrust reviewed and corrected the CDN configuration on July 2 and confirmed full operational status through successful testing that included retrieving CRLs. The bug was marked RESOLVED with resolution FIXED, and IdenTrust stated no additional activities were pending other than including the incident in next year’s annual audit report.
- IdenTrust experienced unusually high traffic to identrust.com that caused intermittent certificate issuance and OCSP validation success, along with OCSP/CRL/revocation availability issues.
- A CDN configuration change inadvertently prevented access to CRLs; the configuration was later reviewed and corrected and CRL retrieval was successfully tested.
- IdenTrust Services, LLC — IdenTrust described the incident timeline, stated the resulting BR/CPS violations (OCSP response time, CRL retrieval failure, and revocation request handling), and reported that a CDN configuration change was corrected after CRL unavailability was identified.
- IdenTrust Services, LLC — IdenTrust stated no additional activities were pending other than including the incident in next year’s annual audit report.
- Mozilla representative — Mozilla indicated it would leave the issue open for another week and close it if there were no questions or new comments by July 27, 2022.