← Certainly LLC cases
Bugzilla #1900129
Certificate Problem Report
Certainly: Serving invalid or incomplete CRLs
RESOLVED
FIXED
Certainly LLC
AI Summary
Certainly LLC experienced an incident where their R1 intermediate issuer CRLs were not updated correctly from May 24 to May 29, 2024. During this time, E1 and R1 CRLs became intermixed, leading to the potential serving of incorrect CRLs. Although no expired CRLs were served, some valid CRLs did not reflect recent revocations. The issue was identified and resolved within hours of discovery, with corrective measures implemented to prevent future occurrences.
Chronology
- R1 CRLs begin to be published incorrectly.
- Issue discovered and CRLs corrected.
- All action items related to the incident are completed.
Participants
Wayne Thayer
Aaron Gable
Mathew Hodson
Daniel Jeffery
External References
Similar Local Cases
Certainly: Serving Expired OCSP Responses
Certainly: Serving Bad OCSP Responses
Certainly: Early CRL Entry Removal
Certainly: Sample Websites Unavailable
Certainly: TLS Using ALPN TLS Version and OID
Let's Encrypt: keyCompromise key blocking deviation from CP/CPS
DigiCert: Inconsistent validation information
Let's Encrypt: OCSP "unauthorized" responses