D-TRUST: CRL not DER-encoded
This case concerns a D-TRUST issue where a CRL distribution point URI returned a PEM-encoded CRL instead of a single DER-encoded CRL, which D-TRUST stated violates RFC5280 section 4.2.1.13. The problem was reported to D-TRUST via Bugzilla on 2022-10-03, and D-TRUST opened Bug 1793440 as a preliminary incident report. D-TRUST investigated and determined the encoding error affected multiple D-TRUST CA certificates: D-TRUST EV CA 1-20-1 2020, and D-TRUST BR CA 1-20-1 2020 and D-TRUST BR CA 1-20-2 2020. D-TRUST explained that CRLs are produced as DER-encoded CRLs in LDAP, but a publication script configuration error encoded some CRLs into PEM due to legacy customer requests for PEM-encoded CRLs. D-TRUST changed the publication script so that encoding of any CRL is no longer possible, regardless of the CA, and reported that the incident was resolved after the necessary actions were taken. D-TRUST stated that further investigations found no additional findings and that there were no further updates planned, pending any questions from Mozilla.
- D-TRUST configured its CRL production procedure.
- D-TRUST configured the script for publishing CRLs on webservers for HTTP download, where the error occurred.
- D-TRUST was informed via Bugzilla that a D-TRUST EV CA CRL distribution point returned a CRL that was not DER-encoded.
- D-TRUST began investigating and decided to change the CRL encoding, including updating the publication script configuration.
- D-TRUST issued the first DER-encoded CRL for the affected issuing CA.
- D-TRUST informed its Conformity Assessment Body about the issue.
- Mm representative — Opened the incident report stating the CRL distribution point URI returned a PEM-encoded CRL and cited RFC5280 4.2.1.13.
- Bdr representative — Confirmed receipt and stated a response would be provided by 19.10.2022.
- Bdr representative — Submitted a preliminary incident report including a timeline, investigation details, and steps to resolve the issue by changing the CRL publication script.
- Bdr representative — Reported that further investigations found no additional findings and that the preliminary report could be considered final.
- Bdr representative — Stated the incident was resolved, that all necessary actions were taken, and that no further updates were planned.
- Mozilla representative — Indicated that if there were no further questions, Mozilla would close the ticket on or about 2-Nov-2022.