Certainly: CRL Issuing Distribution Point mismatch in CCADB (MRSP 6.1.2)
Certainly reported that its CCADB entries for the “JSON Array of Partitioned CRLs” did not precisely match the URL in the Issuing Distribution Point (IDP) extension of its end-entity CRLs, as may be required under section 6.1.2 of MRSP v2.8.1. The issue came to Certainly’s attention after Andrew Ayer announced the CRL Watch website, which listed Certainly’s IDPs as having an error; on 2023-02-20, Certainly personnel checked CRL Watch and identified the discrepancy. In response, Certainly updated CCADB “JSON Array of Partitioned CRLs” entries for its ICAs and corresponding cross-certificate entries, changing the URLs to use HTTP. The CA stated that it had previously believed there was no harm and that the discrepancy was not identified during a later review of the MRSP 2.8.1 redline. Certainly added CRL Watch review to its weekly compliance checklist and stated that all remediation steps were completed. The bug was resolved as FIXED, and Chrome Root Program indicated no further concern from its perspective; Mozilla stated it would close the bug on 2023-03-24.
- Certainly deployed end-entity CRLs and updated CCADB with “JSON Array of Partitioned CRLs” for its ICAs and cross-certs.
- Certainly began issuing sharded CRLs including IDP extensions and updated CCADB to reference the new shards via “JSON Array of Partitioned CRLs” with HTTPS URLs.
- After checking CRL Watch, Certainly identified the CCADB/IDP URL discrepancy and updated CCADB entries to use HTTP URLs.
- Certainly reported that all remediation steps were completed.
- Mozilla closed the bug after no further concerns were raised.
- Fastly representative — Wayne Thayer described that CCADB “JSON Array of Partitioned CRLs” entries did not precisely match the IDP extension URL and outlined the timeline and remediation steps, including updating CCADB to use HTTP URLs and adding CRL Watch to weekly monitoring.
- Fastly representative — Wayne Thayer stated that Certainly completed all remediation steps.
- Fastly representative — Wayne Thayer said there were no further updates but that Certainly would continue monitoring the bug.
- Google representative — Ryan Dickson thanked Wayne and said Chrome Root Program had no further concern and that the report satisfied the CCADB incident-report criteria.
- Fastly representative — Wayne Thayer reiterated that there were no further updates and that Certainly would continue monitoring.
- Mozilla representative — Ben Wilson said the bug would be closed on Friday, 24-Mar-2023, unless other concerns were raised.