← IdenTrust Services, LLC cases
Bugzilla #1914067 Delayed Revocation

IdenTrust: Expired CRLs

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

IdenTrust reported that it served expired certificate revocation lists (CRLs) for about eight hours on 2024-08-18, after two public trust CRLs expired without being renewed. The CA stated this was a violation of Section 4.10.2 of the TLS BRs on Service Availability, and that the CRL expiration potentially affected certificate validation for certificates issued under these trust anchors. IdentiTrust said it renewed the CRLs and reconfigured its alert system, and it also rolled back a server OS update earlier in the day. In its complete incident report, the CA attributed the issue to a server OS update that altered background processes affecting certificate management workflow, combined with a misconfigured Nagios alerting setup that failed to detect the CRLs past their signing date. The CA reported that no certificates were affected. The bug is marked RESOLVED/FIXED, with Mozilla indicating it would close the case on 18-Oct-2024 unless additional issues were discussed.

Model: gpt-5.4-nano Generated: 2026-06-13 21:29 UTC Revised: 2026-06-16 19:27 UTC Confidence: 0.86 8 comments
Chronology
  1. Two public trust CRLs expired without being renewed, leading to expired CRLs being served for about eight hours.
  2. IdenTrust renewed the CRLs and recreated the affected CRLs after troubleshooting and rollback actions.
  3. IdenTrust reported fixes to Nagios monitoring/alerting and successful testing of the corrected alerting behavior.
  4. IdenTrust stated there were no additional updates and the issue was closed/resolved on its side.
Thread Activity
  1. IdenTrust Services, LLC — IdenTrust reported that monitoring alerts indicated expired CRLs were publicly available and described an initial incident summary, including a suspected scheduled software change control and rollback.
  2. IdenTrust Services, LLC — IdenTrust posted a complete incident report with impact, timeline, root cause analysis, and action items, stating that no certificates were affected.
  3. Community commenter — Kumaresh Somi asked for clarity on the monitoring/alerting system and whether alert escalation would be implemented for impending CRL expiry.
  4. IdenTrust Services, LLC — IdenTrust explained its monitoring approach (Nagios and PagerDuty), stated the incident was caused by a Nagios misconfiguration, and said the alerting process was fixed and tested.
  5. IdenTrust Services, LLC — IdenTrust reported improvements to debugging capabilities merged into its configuration management codebase.
  6. IdenTrust Services, LLC — IdenTrust stated there were no additional updates and the issue was considered closed/resolved on its side.
  7. Mozilla representative — Mozilla stated it would close the bug on Friday, 18-Oct-2024, unless additional issues were discussed.
Participants
IdenTrust Services, LLC Mozilla representative Community commenter
External References
Similar Local Cases
#1853447 RESOLVED Delayed Revocation Opened 2023-09-15 · Closed 2023-10-12 · 98% similar
IdenTrust: Temporarily Expired CRLs
#1792111 RESOLVED Delayed Revocation Incident Opened 2022-09-22 · Closed 2023-02-22 · 98% similar
IdenTrust: Expired CRLs
#1870402 RESOLVED Delayed Revocation Opened 2023-12-15 · Closed 2024-06-30 · 97% similar
IdenTrust: Expired CRL served
#1678410 RESOLVED Delayed Revocation Opened 2020-11-19 · Closed 2023-02-22 · 97% similar
IdenTrust: Invalid OCSP Response Held in Cache
#1736706 RESOLVED Delayed Revocation Opened 2021-10-19 · Closed 2023-02-22 · 96% similar
IdenTrust: Failure to Revoke Subscriber Certificates Within 5 days
#1757247 RESOLVED Delayed Revocation Opened 2022-02-25 · Closed 2023-02-22 · 95% similar
IdenTrust: Delay Revocation for EV SSL Certificates
#1851710 RESOLVED Delayed Revocation Opened 2023-09-05 · Closed 2024-01-04 · 94% similar
IdenTrust: Delay beyond 5 days in revoking misissued certificates
#1692535 RESOLVED Delayed Revocation Opened 2021-02-12 · Closed 2023-02-22 · 75% similar
Camerfirma: Delayed revocations of certificates issued by old CAs with an RSA modulus size of 2047 bits

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action