Apple: CRLs for dormant CAs will not be populated in CCADB
Apple Public CA reported that it would not provide CRLs for eight dormant CA certificates (capable of issuing TLS certificates) to root vendors for population in CCADB by October 1, 2022. Apple stated its understanding of Mozilla Root Store Policy v2.8 was that dormant CAs that have never produced a CRL nor signed a certificate are not required to provide “Full CRLs” to root vendors. The bug describes the policy timing and Apple’s discussions with root vendors about the approach for Apple’s dormant CAs. Sectigo, which issued two of the CA certificates, said it started adding required CRL data into CCADB on September 22, 2022, but observed two CA certificates listed as missing the required CRL data and coordinated with Apple on the incident report. DigiCert commented that the bug was filed for completeness because non-issuing ICAs are not officially excluded from Mozilla policy, and noted an unofficial exception discussed in an email. Mozilla’s bwilson said Mozilla did not consider this an “incident” but a “disclosure,” tagged it informational, and closed the bug. The bug is resolved as FIXED.
- Mozilla Root Store Policy v2.8 effective date for CCADB full-CRL disclosure requirements.
- Sectigo began adding required CRL data into CCADB for disclosed and unexpired intermediate certificates issued directly by Sectigo.
- Apple opened the bug describing its plan not to provide CRLs for eight dormant CA certificates to root vendors for CCADB population by the October 1 deadline.
- Mozilla tagged the bug as informational and closed it.
- Apple representative — Apple explained that it would not provide CRLs for eight dormant CA certificates to root vendors for CCADB population by October 1, 2022, citing its understanding of Mozilla Root Store Policy v2.8.
- Sectigo — Sectigo acknowledged Apple’s report, described its CCADB population work starting September 22, 2022, and said it found two intermediates missing CRL data and coordinated with Apple on filing.
- DigiCert — DigiCert said the bug was filed for completeness because non-issuing ICAs are not officially excluded from Mozilla policy, and referenced an unofficial exception discussed in an email.
- Sectigo — Sectigo added that it used the CCADB API to populate the “Full CRL Issued By This CA” field, noticed two intermediates lacking CRL disclosures via crt.sh views, and discussed policy precedence and coordination with Apple.
- Mozilla representative — Mozilla stated it did not consider this an “incident” but a “disclosure,” tagged the bug as informational, and closed it.