IdenTrust: Expired ICAs CRLs
IdenTrust reported that one of its CRL repository nodes failed to update properly, causing CRL Watch to flag an error for an IdenTrust ICA CRL. The CA stated that this could have resulted in up to one-third of CRL requests returning an “expired CRL” status response, because the impacted node provided expired CRL responses for 5 hours and 2 minutes while other nodes in a round-robin configuration continued to serve valid CRLs. IdenTrust said certificate issuance was not affected and that the CRL replication failure was resolved promptly after diagnosis. In response, IdenTrust removed the impacted server from the round-robin pool at 08:07 MDT on 2023-08-31 and later reviewed logs to confirm the duration of CRL expiration for the affected CRLs. The thread states that no certificates were affected and that the issue was corrected. The bug is marked RESOLVED with resolution FIXED.
- IdenTrust’s CRL repository node failed to update properly, leading to expired CRL responses for a period of time.
- IdenTrust Services, LLC — IdenTrust described noticing a CRL Watch parsing/update error on 2023-08-31, confirmed the replication failure, and documented remediation steps including removing the impacted server from the round-robin pool; it also stated certificate issuance was not affected and no certificates were affected.
- IdenTrust Services, LLC — IdenTrust stated it implemented stricter procedures for future equipment upgrades, including monitoring improvements before and after installation, and that there were no outstanding action items.
- Mozilla representative — Mozilla indicated they would schedule closure of the bug next Wed (1-Nov-2023) unless there were comments or questions.