← IdenTrust Services, LLC cases
Bugzilla #1794047
Certificate Problem Report
IdenTrust: Missing Revocation Reasons in CRL
RESOLVED
FIXED
IdenTrust Services, LLC
AI Summary
IdenTrust identified a compliance issue where a Certificate Revocation List (CRL) was missing revocation reasons for revoked certificates, violating Mozilla Root Store Policy and IdenTrust CPS. The issue was traced back to a failed database update during a software change control on October 1, 2022. After remediation, IdenTrust confirmed that current CRLs are correct. A formal incident report was provided detailing the timeline and corrective actions taken to prevent future occurrences.
Chronology
- IdenTrust deployed a release to update revocation reason codes.
- Routine quality check suspected CRLs were not generated properly.
- Investigation revealed a database update failed to execute.
- Confirmed missing revocation reasons in the CRL.
- Formal incident report submitted.
Participants
IdenTrust
Mozilla
External References
Similar Local Cases
IdenTrust: Bad OCSP Responses
IdenTrust: Failure to provide OCSP responses for valid ICA certificates
IdenTrust: CRL Potential Publication Delay due to Cache
IdenTrust: Unavailable CRL for IdenTrust ‘DST Root CA X3’.
IdenTrust: TLS self audit testing below 3%
IdenTrust: Expired CRLs
IdenTrust: TLS ICA with User Notice in Policy Qualifier
IdenTrust: Expired ICAs CRLs