← DigiCert cases
Bugzilla #1820269 Ca Security Vulnerability Security Incident

DigiCert: CRL and OCSP availability issues due to CDN misconfiguration (resolved)

RESOLVED FIXED DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case describes a DigiCert incident where CRL responses were unavailable or returned 404 errors for four CRL URLs. DigiCert said it first became aware of the problem by monitoring SSLMate’s CRL-Watch website and noticing four CRLs listed with 404 errors. DigiCert reported that the issue was triggered by a misconfigured path in its CDN after a CDN migration, specifically that the origin path for kr.crl.digicert.com was misconfigured when the old CDN was shut down. DigiCert stated that Engineering resolved the CDN misconfiguration and pushed the change to the CDN, after which Engineering started receiving correct responses from the affected domain. DigiCert also reported that Apple notified it of stale OCSP responses, leading to an investigation and manual OCSP pushes to keep data fresh until the issue was isolated and confirmed fixed. DigiCert stated that the CRL misconfiguration and stale OCSP responses had no impact on certificates issued, and that remediation was completed; the bug was resolved with resolution FIXED. DigiCert further stated it implemented monitoring for CRL availability/age across all CRL distribution endpoints listed in CCADB and completed OCSP monitoring enhancements.

Model: gpt-5.4-nano Generated: 2026-06-13 11:42 UTC Revised: 2026-06-16 19:10 UTC Confidence: 0.88 9 comments
Chronology
  1. DigiCert migrated its CDN for CRL/OCSP, during which some configurations were missed.
  2. DigiCert personnel discovered CRL problems (four CRLs returning 404) and Engineering resolved the CDN misconfiguration.
  3. Apple notified DigiCert of stale OCSP responses, prompting investigation and manual OCSP pushes.
  4. DigiCert confirmed the OCSP/related issue was fixed.
  5. DigiCert implemented CRL monitoring and reported OCSP monitoring enhancements were still in progress.
  6. DigiCert reported OCSP monitoring was completed and live.
  7. DigiCert reported remediation was complete and requested closure; Mozilla indicated intent to close on 2023-06-14.
Thread Activity
  1. Community commenter — Martin Sullivan reported that DigiCert noticed four CRLs with 404 errors on SSLMate’s CRL-Watch, described the CDN misconfiguration cause, and outlined remediation and monitoring changes.
  2. Community commenter — Martin Sullivan said that during investigation DigiCert found other irregularities linked to the change and planned a revised bug report.
  3. Google representative — Ryan Dickson asked Martin Sullivan to add specificity about the meaning of the proposed change-management auditing and to provide more detail on anticipated timing.
  4. Community commenter — Martin Sullivan provided an updated timeline including Apple’s notification of stale OCSP responses, described the CDN migration/configuration issues, and reiterated monitoring and review-process changes.
  5. Community commenter — Martin Sullivan stated that if there were no further questions, DigiCert would provide the next update on April 28 and would continue constant monitoring.
  6. Community commenter — Martin Sullivan reported that CRL monitoring was implemented to monitor all CRLs per the CCADB list, and that OCSP monitoring enhancements were still in progress with an update planned end of month.
  7. Community commenter — Martin Sullivan reported OCSP monitoring was completed and live, and that CRL testing alerts were working in a real-world environment.
  8. Community commenter — Martin Sullivan stated remediation was complete and asked to close the bug.
  9. Mozilla representative — Ben Wilson said he intended to close the bug on 2023-06-14-2023.
Participants
Community commenter Mozilla representative Google representative
Similar Local Cases
#1744795 RESOLVED Ca Security Vulnerability Security Incident Opened 2021-12-07 · Closed 2023-02-22 · 91% similar
DigiCert: Issuance of certs with weak keys (ROCA)
#1816806 RESOLVED Ca Security Vulnerability Security Incident Opened 2023-02-15 · Closed 2023-03-09 · 91% similar
DigiCert: OCSP not responding issue
#1662346 RESOLVED Ca Security Vulnerability Security Incident Opened 2020-09-01 · Closed 2023-02-22 · 89% similar
DigiCert: OCSP responder returning invalid responses
#1675684 RESOLVED Ca Security Vulnerability Security Incident Opened 2020-11-06 · Closed 2023-02-22 · 88% similar
DigiCert: Private Keys Disclosed by Customers as Part of CSR
#1577014 RESOLVED Security Incident Opened 2019-08-27 · Closed 2023-02-22 · 80% similar
DigiCert: OCSP services returns 1 byte
#1424305 RESOLVED Ca Security Vulnerability Incident Opened 2017-12-08 · Closed 2023-02-22 · 79% similar
DigiCert: Microsoft: Incident report for Microsoft Dynamics incident
#1878106 RESOLVED Ca Security Vulnerability Security Incident Opened 2024-02-01 · Closed 2024-03-08 · 69% similar
HARICA: Anomaly in OCSP services after CA software upgrade
#1427034 RESOLVED Ca Security Vulnerability Security Incident Opened 2017-12-25 · Closed 2024-05-09 · 69% similar
DigiCert: localbattle.net certificate with private key in software / issued by Digicert

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action