← e-commerce monitoring GmbH cases
Bugzilla #1888371 Incident

e-commerce monitoring GmbH: CRLs with mismatched issuer

RESOLVED WONTFIX e-commerce monitoring GmbH
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

e-commerce monitoring GmbH disclosed a compliance failure regarding the issuance of two Certificate Revocation Lists (CRLs) that did not meet the CA/Browser Forum Baseline Requirements. The issue was identified on March 25, 2024, when the CRLs were found to have mismatched issuer information. The CA acknowledged the problem and initiated an internal investigation, confirming that a recent database update led to the incorrect configuration. Despite efforts to implement a workaround, the issue persisted, prompting further scrutiny from Mozilla and other root programs. As of June 30, 2024, e-commerce monitoring GmbH's root certificate will be removed from browser root programs due to ongoing compliance issues, although previously issued certificates will remain valid.

Model: gpt-4o-mini Generated: 2026-06-13 21:24 UTC Revised: 2026-06-16 18:34 UTC Confidence: 0.85 20 comments
Chronology
  1. e-commerce monitoring GmbH issued two CRLs with mismatched issuer information.
  2. e-commerce monitoring GmbH's root certificate will be removed from browser root programs.
Thread Activity
  1. Mm representative — Created bug report regarding the mismatched issuer in CRLs.
  2. e-commerce monitoring GmbH — Confirmed receipt of the report and stated they are gathering information.
  3. e-commerce monitoring GmbH — Provided an incident report detailing the root cause and action items.
  4. e-commerce monitoring GmbH — Announced the decision to remove e-commerce monitoring GmbH from root programs.
Participants
Mm representative e-commerce monitoring GmbH Google representative Mozilla representative Community commenter Apple representative
External References
Similar Local Cases
#1893546 RESOLVED Incident Opened 2024-04-25 · Closed 2024-07-09 · 100% similar
e-commerce monitoring gmbh: failure to follow incident report requirements
#1819105 RESOLVED Incident Opened 2023-02-27 · Closed 2023-09-29 · 84% similar
NETLOCK: Disclosed CRL is expired
#1758372 RESOLVED Incident Opened 2022-03-07 · Closed 2023-02-22 · 76% similar
Google Trust Services: Incorrect OCSP response for issued certificate
#1688215 RESOLVED Ca Documents Incident Policy Document Issue Opened 2021-01-22 · Closed 2023-02-22 · 75% similar
Camerfirma: CP/CPS of Intesa Sanpaolo Sub-CA is Non-Compliant
#1647084 RESOLVED Self Reported Incident Incident Opened 2020-06-20 · Closed 2023-02-22 · 75% similar
DigiCert / Microsoft: inconsistent disclosure of externally-operated intermediate
#1949203 RESOLVED Incident Opened 2025-02-19 · Closed 2025-04-03 · 75% similar
Actalis: two CAs with the same CRLDP
#1825780 RESOLVED Incident Self Reported Incident Opened 2023-03-31 · Closed 2023-07-05 · 74% similar
Telekom Security: Improper use of a domain validation method
#1932973 RESOLVED Certificate Misissuance Incident Opened 2024-11-22 · Closed 2025-04-07 · 74% similar
SSL.com: CAA Empty set handling results in Wildcard issuance

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action