D-Trust: LDAP-URL in Subscriber Certificate Authority Information Access field
D-Trust issued TLS certificates containing an LDAP-URL in the Subscriber Certificate Authority Information Access field after September 15, 2023. Upon discovering this issue, D-Trust adjusted its certificate profiles to exclude LDAP entries in future products and decided to revoke the affected certificates. On March 15, 2024, D-Trust revoked a total of 2,601 certificates as a precautionary measure. The root cause was identified as a misinterpretation of the Baseline Requirements regarding the inclusion of LDAP URLs, which D-Trust acknowledged as a formal violation. The CA has since committed to improving its compliance processes and tools.
- D-Trust revoked 2,601 TLS certificates due to the inclusion of an LDAP-URL in the Subscriber Certificate Authority Information Access field.
- Bdr representative — D-Trust decided to revoke the affected TLS certificates within 5 days.
- D-Trust — All affected TLS certificates were revoked.
- Bdr representative — A new incident report was opened regarding two certificates without a CT log entry.