← Certainly LLC cases
Bugzilla #1819422 Policy Document Issue

Certainly: CRL Issuing Distribution Point mismatch in CCADB (MRSP 6.1.2)

RESOLVED FIXED Certainly LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Certainly reported that its CCADB entries for the “JSON Array of Partitioned CRLs” did not precisely match the URL in the Issuing Distribution Point (IDP) extension of its end-entity CRLs, as may be required under section 6.1.2 of MRSP v2.8.1. The issue came to Certainly’s attention after Andrew Ayer announced the CRL Watch website, which listed Certainly’s IDPs as having an error; on 2023-02-20, Certainly personnel checked CRL Watch and identified the discrepancy. In response, Certainly updated CCADB “JSON Array of Partitioned CRLs” entries for its ICAs and corresponding cross-certificate entries, changing the URLs to use HTTP. The CA stated that it had previously believed there was no harm and that the discrepancy was not identified during a later review of the MRSP 2.8.1 redline. Certainly added CRL Watch review to its weekly compliance checklist and stated that all remediation steps were completed. The bug was resolved as FIXED, and Chrome Root Program indicated no further concern from its perspective; Mozilla stated it would close the bug on 2023-03-24.

Model: gpt-5.4-nano Generated: 2026-06-13 21:28 UTC Revised: 2026-06-16 18:17 UTC Confidence: 0.86 6 comments
Chronology
  1. Certainly deployed end-entity CRLs and updated CCADB with “JSON Array of Partitioned CRLs” for its ICAs and cross-certs.
  2. Certainly began issuing sharded CRLs including IDP extensions and updated CCADB to reference the new shards via “JSON Array of Partitioned CRLs” with HTTPS URLs.
  3. After checking CRL Watch, Certainly identified the CCADB/IDP URL discrepancy and updated CCADB entries to use HTTP URLs.
  4. Certainly reported that all remediation steps were completed.
  5. Mozilla closed the bug after no further concerns were raised.
Thread Activity
  1. Fastly representative — Wayne Thayer described that CCADB “JSON Array of Partitioned CRLs” entries did not precisely match the IDP extension URL and outlined the timeline and remediation steps, including updating CCADB to use HTTP URLs and adding CRL Watch to weekly monitoring.
  2. Fastly representative — Wayne Thayer stated that Certainly completed all remediation steps.
  3. Fastly representative — Wayne Thayer said there were no further updates but that Certainly would continue monitoring the bug.
  4. Google representative — Ryan Dickson thanked Wayne and said Chrome Root Program had no further concern and that the report satisfied the CCADB incident-report criteria.
  5. Fastly representative — Wayne Thayer reiterated that there were no further updates and that Certainly would continue monitoring.
  6. Mozilla representative — Ben Wilson said the bug would be closed on Friday, 24-Mar-2023, unless other concerns were raised.
Participants
Fastly representative Community commenter Google representative Mozilla representative
Similar Local Cases
#1662810 RESOLVED Policy Document Issue Opened 2020-09-02 · Closed 2023-02-22 · 58% similar
GoDaddy: DV certificates with organizationalUnit field in subject
#1793642 RESOLVED Policy Document Issue Opened 2022-10-04 · Closed 2025-07-08 · 48% similar
GoDaddy: CRLs are version 1 and lack CRL Number extension
#1705904 RESOLVED Policy Document Issue Self Reported Incident Opened 2021-04-17 · Closed 2023-02-22 · 45% similar
KIR S.A.: CP/CPS contains noncompliant DV method, does not specify CAA domains
#1942651 RESOLVED Self Reported Incident Policy Document Issue Opened 2025-01-20 · Closed 2025-02-14 · 41% similar
Sectigo / SSL.com: Late disclosure of updated SSL.com CP/CPS to CCADB
#1942651 RESOLVED Self Reported Incident Policy Document Issue Opened 2025-01-20 · Closed 2025-02-14 · 41% similar
Sectigo / SSL.com: Late disclosure of updated SSL.com CP/CPS to CCADB
#1545208 RESOLVED Policy Document Issue Opened 2019-04-17 · Closed 2023-02-22 · 41% similar
Sectigo: Missing Changelog in CPS
#1947034 RESOLVED Policy Document Issue Self Reported Incident Opened 2025-02-09 · Closed 2025-04-11 · 41% similar
Chunghwa Telecom: outdated and stale policy documents disclosed to the CCADB
#1771727 RESOLVED Audit Finding Policy Document Issue Opened 2022-05-30 · Closed 2023-02-22 · 41% similar
Firmaprofesional: 2022 - Define Device Obsolescence Process

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action