← Apple Inc. cases
Bugzilla #1793210
Certificate Problem Report
Apple: CRLs for dormant CAs will not be populated in CCADB
RESOLVED
FIXED
Apple Inc.
AI Summary
Apple Inc. reported that it would not populate the CCADB with CRLs for eight dormant CA certificates capable of issuing TLS certificates, as they have never produced a CRL nor signed a certificate. This decision was made in light of the Mozilla Root Store Policy requirements effective October 1, 2022. The incident raised discussions among involved parties, including Sectigo and DigiCert, regarding compliance with the policy and the implications for non-issuing CAs. Ultimately, the case was resolved with the understanding that the policy would be updated to clarify requirements for dormant CAs.
Chronology
- DigiCert issued six CAs to Apple.
- Sectigo issued two CAs to Apple.
- Mozilla Root Store Policy version 2.8 effective.
- Mozilla noted intent to modify policy.
- Apple concluded discussions with root vendors.
- Apple Root Program Policy updated.
- Incident report acknowledged by Sectigo.
Participants
certification_authority@apple.com
tim.callan@sectigo.com
jeremy.rowley@digicert.com
bwilson@mozilla.com
External References
Similar Local Cases
Apple: Revocation Delay for TLS certificates issued outside the TTL of the CAA record
Apple: Public Key Reuse
Apple: TLS certificates issued outside the TTL of the CAA record
Apple: Test website certificates expired
Apple: EV Certificate Approver Authorization
Apple: OCSP availability 2020-11-12
Apple: OCSP responders return responses with incorrect issuer
Apple: OCSP responders return ‘unknown’ for valid S/MIME and TLS certificates