← IdenTrust Services, LLC cases
Bugzilla #1854465
Certificate Problem Report
IdenTrust: Expired ICAs CRLs
RESOLVED
FIXED
IdenTrust Services, LLC
AI Summary
IdenTrust Services, LLC reported an issue where one of its Intermediate Certificate Authorities (ICAs) had an expired Certificate Revocation List (CRL) due to a failure in updating one of its CRL repository nodes. This incident was detected on August 31, 2023, and resulted in expired CRL responses for a duration of up to 5 hours and 2 minutes for some requests. However, the issue was promptly resolved by removing the affected server from the round-robin configuration, and no certificates were impacted by this incident.
Chronology
- IdenTrust noticed the expired CRL issue and began investigation.
- The issue was resolved by removing the impacted server from the round-robin pool.
- IdenTrust implemented stricter procedures for future equipment upgrades.
- Scheduled closure of the case unless further comments are received.
Participants
IdenTrust
Mozilla
External References
Similar Local Cases
IdenTrust: Expired CRLs
IdenTrust: Unavailable CRL for IdenTrust ‘DST Root CA X3’.
IdenTrust: Failure to provide OCSP responses for valid ICA certificates
IdenTrust: CRL Potential Publication Delay due to Cache
IdenTrust: Bad OCSP Responses
IdenTrust: TLS ICA with User Notice in Policy Qualifier
IdenTrust: Pre-certificates without a final certificate showing OCSP error
IdenTrust: Missing Revocation Reasons in CRL