← IdenTrust Services, LLC cases
Bugzilla #1870402
Certificate Problem Report
IdenTrust: Expired CRL served
RESOLVED
FIXED
IdenTrust Services, LLC
AI Summary
IdenTrust experienced an incident where expired Certificate Revocation Lists (CRLs) were served due to a failure in the regular CRL checking process. This issue was detected on December 6, 2023, and involved 26 CRLs that were expired for a duration of 81 to 119 minutes, violating CA/B Forum requirements. The root cause was linked to a new network file system service that had incorrect permissions, preventing the publication of new CRLs. The situation was promptly addressed, and no pending remediation actions remain.
Chronology
- Alerts indicated failure in CRL checking process.
- Investigation into the expired CRLs began.
- Incident report detailing the issue was provided.
- Confirmed no pending remediation actions.
- Case closure anticipated by January 24, 2024.
Participants
roots@identrust.com
bwilson@mozilla.com
External References
Similar Local Cases
IdenTrust: Unauthorized OCSP response on a Timestamp certificate
IdenTrust: Unavailable CRL and OCSP Responders
IdenTrust: TLS Certificates with outdated certificate profile
IdenTrust: Undisclosed Unrevoked ICAs
IdenTrust: EV TLS certificate with invalid Jurisdiction state for government entity
IdenTrust: S/MIME certificates with Invalid document Identification Scheme
IdenTrust: Temporarily Expired CRLs
IdenTrust: Expired ICAs CRLs