FNMT: CRL problems displayed during the monitoring
The case concerns CRL problems that were displayed during monitoring on SSLMate’s CRL-Watch website for FNMT. FNMT said it became aware of the issue when Ben Wilson notified it that there were errors with 7 of its CRLs shown on SSLMate’s CRL-Watch site on April 14. FNMT’s compliance team confirmed the finding and initially saw errors reported as “i/o timeout,” then escalated to engineering. Engineering checked CRL response status and verified the CRLs were fine, accessible, and downloadable, while noting response time could be longer due to a DDoS attack and mitigation measures activated that morning. After further analysis, FNMT concluded the displayed errors were communication errors and later detected “403 Forbidden” errors on April 16, which it attributed to the CRL-Watch script’s request pattern matching the DDoS attack and being blocked. FNMT reported that its IPS completed mitigation and removed traffic blocks on April 17, and that the errors were removed from CRL Watch by April 17. The bug was resolved as FIXED, and FNMT stated that monitoring at SSLMate’s CRL Watch website had been configured in its 24x7 alert system.
- FNMT received notification that SSLMate’s CRL-Watch displayed errors for 7 FNMT CRLs.
- FNMT detected “403 Forbidden” errors on SSLMate’s CRL-Watch and escalated to engineering.
- FNMT’s IPS completed mitigation and removed traffic blocks; CRL-Watch errors were confirmed removed.
- Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — Created the bug and attached a report titled “CRL problems displayed during the monitoring.pdf,” describing how FNMT became aware of the SSLMate CRL-Watch errors and the actions taken.
- Government of Spain, Fábrica Nacional de Moneda y Timbre (FNMT) — Stated that monitoring at SSLMate’s CRL Watch website has been configured in FNMT’s 24x7 alert system.
- Mozilla representative — Indicated intent to close the bug on Friday, 29-Sept-2023 unless there were items to discuss.