e-commerce monitoring GmbH: CRLs with mismatched issuer
e-commerce monitoring GmbH disclosed a compliance failure regarding the issuance of two Certificate Revocation Lists (CRLs) that did not meet the CA/Browser Forum Baseline Requirements. The issue was identified on March 25, 2024, when the CRLs were found to have mismatched issuer information. The CA acknowledged the problem and initiated an internal investigation, confirming that a recent database update led to the incorrect configuration. Despite efforts to implement a workaround, the issue persisted, prompting further scrutiny from Mozilla and other root programs. As of June 30, 2024, e-commerce monitoring GmbH's root certificate will be removed from browser root programs due to ongoing compliance issues, although previously issued certificates will remain valid.
- e-commerce monitoring GmbH issued two CRLs with mismatched issuer information.
- e-commerce monitoring GmbH's root certificate will be removed from browser root programs.
- Mm representative — Created bug report regarding the mismatched issuer in CRLs.
- e-commerce monitoring GmbH — Confirmed receipt of the report and stated they are gathering information.
- e-commerce monitoring GmbH — Provided an incident report detailing the root cause and action items.
- e-commerce monitoring GmbH — Announced the decision to remove e-commerce monitoring GmbH from root programs.