← e-commerce monitoring GmbH cases
Bugzilla #1888371
Certificate Problem Report
e-commerce monitoring GmbH: CRLs with mismatched issuer
RESOLVED
WONTFIX
e-commerce monitoring GmbH
AI Summary
e-commerce monitoring GmbH issued two Certificate Revocation Lists (CRLs) that did not comply with the Baseline Requirements, specifically regarding the issuer field not matching the subject field of the issuing CA. This incident was reported on March 28, 2024, and while a workaround was initially found, it was later abandoned as the issue persisted. The company has acknowledged the problem and is restructuring its processes to regain compliance, as they face removal from major root programs effective June 30, 2024.
Chronology
- e-commerce monitoring GmbH issued two CRLs with mismatched issuer.
- Bug filed regarding the CRLs.
- Company confirmed a workaround was found.
- Company acknowledged that the workaround was abandoned.
- Company announced removal from root programs effective June 30, 2024.
Participants
Andrew Ayer
Daniel Zens
External References
Similar Local Cases
e-commerce monitoring GmbH: Revoked test website not using revoked certificate
e-commerce monitoring GmbH: CN domain not in SAN
e-commerce monitoring GmbH: SCT in precertificate
e-commerce monitoring gmbh: precertificate validity does not match leaf certificate
NETLOCK: Disclosed CRL is expired
DigiCert / Microsoft: inconsistent disclosure of externally-operated intermediate
SECOM: FUJIFILM intermediate CA Certificate not listed in audit statement
GRCA: Signing SHA-1 OCSP responses with unconstrained certificate