IdenTrust: Expired CRL served
IdenTrust reported that its normal CRL checking process failed, resulting in out-of-date (expired) CRLs being served. The incident was detected by CRL monitoring alerts on 2023-12-06, and the CA stated that 26 CRLs had expired for about 81 to 119 minutes, impacting 10 publicly trusted CRLs. The CA attributed the root cause to a newly introduced network file system sharing service with default directory permissions set to “Root,” which caused “permission denied” errors when publishing new 30-day CRLs; the new CRLs were removed, leaving the outdated ones expired. IdenTrust said it addressed the issue the same day by discontinuing the recently introduced service and writing new CRLs and updates directly to their intended destinations. The thread includes an incident report and states that there were no pending remediation actions. The bug is marked RESOLVED with resolution FIXED.
- IdenTrust’s CRL monitoring detected a failure in regular CRL checking, during which multiple CRLs expired and were served as out-of-date.
- IdenTrust posted a full incident report describing the impact, timeline, root cause, and corrective actions.
- IdenTrust stated there were no pending remediation actions for the issue.
- Mozilla indicated it would close the bug on or about 24-Jan-2024.
- IdenTrust Services, LLC — IdenTrust reported that alerts showed CRL checking failure leading to out-of-date CRLs being served, and said it would provide a full incident report by 2023-12-29.
- IdenTrust Services, LLC — IdenTrust provided an incident report stating 26 CRLs expired for 81–119 minutes, impacting 10 publicly trusted CRLs, and explained the permission-denied root cause and remediation steps.
- IdenTrust Services, LLC — IdenTrust stated it had no pending remediation actions for the issue.
- Mozilla representative — Mozilla said it would close the bug on or about 24-Jan-2024.