← Apple Inc. cases
Bugzilla #1793210 Incident

Apple: CRLs for dormant CAs will not be populated in CCADB

RESOLVED FIXED Apple Inc.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Apple Public CA reported that it would not provide CRLs for eight dormant CA certificates (capable of issuing TLS certificates) to root vendors for population in CCADB by October 1, 2022. Apple stated its understanding of Mozilla Root Store Policy v2.8 was that dormant CAs that have never produced a CRL nor signed a certificate are not required to provide “Full CRLs” to root vendors. The bug describes the policy timing and Apple’s discussions with root vendors about the approach for Apple’s dormant CAs. Sectigo, which issued two of the CA certificates, said it started adding required CRL data into CCADB on September 22, 2022, but observed two CA certificates listed as missing the required CRL data and coordinated with Apple on the incident report. DigiCert commented that the bug was filed for completeness because non-issuing ICAs are not officially excluded from Mozilla policy, and noted an unofficial exception discussed in an email. Mozilla’s bwilson said Mozilla did not consider this an “incident” but a “disclosure,” tagged it informational, and closed the bug. The bug is resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 15:13 UTC Revised: 2026-06-16 18:04 UTC Confidence: 0.86 5 comments
Chronology
  1. Mozilla Root Store Policy v2.8 effective date for CCADB full-CRL disclosure requirements.
  2. Sectigo began adding required CRL data into CCADB for disclosed and unexpired intermediate certificates issued directly by Sectigo.
  3. Apple opened the bug describing its plan not to provide CRLs for eight dormant CA certificates to root vendors for CCADB population by the October 1 deadline.
  4. Mozilla tagged the bug as informational and closed it.
Thread Activity
  1. Apple representative — Apple explained that it would not provide CRLs for eight dormant CA certificates to root vendors for CCADB population by October 1, 2022, citing its understanding of Mozilla Root Store Policy v2.8.
  2. Sectigo — Sectigo acknowledged Apple’s report, described its CCADB population work starting September 22, 2022, and said it found two intermediates missing CRL data and coordinated with Apple on filing.
  3. DigiCert — DigiCert said the bug was filed for completeness because non-issuing ICAs are not officially excluded from Mozilla policy, and referenced an unofficial exception discussed in an email.
  4. Sectigo — Sectigo added that it used the CCADB API to populate the “Full CRL Issued By This CA” field, noticed two intermediates lacking CRL disclosures via crt.sh views, and discussed policy precedence and coordination with Apple.
  5. Mozilla representative — Mozilla stated it did not consider this an “incident” but a “disclosure,” tagged the bug as informational, and closed it.
Participants
Apple representative Sectigo DigiCert Mozilla representative
Similar Local Cases
#1730291 RESOLVED Incident Opened 2021-09-11 · Closed 2024-06-30 · 97% similar
Apple: Test website certificates expired
#1724528 RESOLVED Incident Opened 2021-08-06 · Closed 2024-06-30 · 96% similar
Apple: Intermediate CA certificates omitted from audit statement
#1659316 RESOLVED Incident Opened 2020-08-16 · Closed 2023-02-22 · 95% similar
Apple: EV Certificate Approver Authorization
#1669618 RESOLVED Incident Opened 2020-10-07 · Closed 2023-02-22 · 94% similar
Apple: Empty SingleExtension in OCSP responses
#1771398 RESOLVED Incident Opened 2022-05-26 · Closed 2023-02-22 · 94% similar
Apple: OCSP responders return ‘unknown’ for valid S/MIME and TLS certificates
#1772644 RESOLVED Incident Opened 2022-06-04 · Closed 2023-02-22 · 94% similar
Apple: CRL issuance frequency deviates from CPS in some cases
#1677234 RESOLVED Incident Opened 2020-11-13 · Closed 2023-02-22 · 93% similar
Apple: OCSP availability 2020-11-12
#1902310 RESOLVED Incident Opened 2024-06-13 · Closed 2024-07-11 · 75% similar
Sectigo: Trusted Role Access provided prior to completion of onboarding process

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action