IdenTrust: Expired CRLs
IdenTrust reported that it served expired certificate revocation lists (CRLs) for about eight hours on 2024-08-18, after two public trust CRLs expired without being renewed. The CA stated this was a violation of Section 4.10.2 of the TLS BRs on Service Availability, and that the CRL expiration potentially affected certificate validation for certificates issued under these trust anchors. IdentiTrust said it renewed the CRLs and reconfigured its alert system, and it also rolled back a server OS update earlier in the day. In its complete incident report, the CA attributed the issue to a server OS update that altered background processes affecting certificate management workflow, combined with a misconfigured Nagios alerting setup that failed to detect the CRLs past their signing date. The CA reported that no certificates were affected. The bug is marked RESOLVED/FIXED, with Mozilla indicating it would close the case on 18-Oct-2024 unless additional issues were discussed.
- Two public trust CRLs expired without being renewed, leading to expired CRLs being served for about eight hours.
- IdenTrust renewed the CRLs and recreated the affected CRLs after troubleshooting and rollback actions.
- IdenTrust reported fixes to Nagios monitoring/alerting and successful testing of the corrected alerting behavior.
- IdenTrust stated there were no additional updates and the issue was closed/resolved on its side.
- IdenTrust Services, LLC — IdenTrust reported that monitoring alerts indicated expired CRLs were publicly available and described an initial incident summary, including a suspected scheduled software change control and rollback.
- IdenTrust Services, LLC — IdenTrust posted a complete incident report with impact, timeline, root cause analysis, and action items, stating that no certificates were affected.
- Community commenter — Kumaresh Somi asked for clarity on the monitoring/alerting system and whether alert escalation would be implemented for impending CRL expiry.
- IdenTrust Services, LLC — IdenTrust explained its monitoring approach (Nagios and PagerDuty), stated the incident was caused by a Nagios misconfiguration, and said the alerting process was fixed and tested.
- IdenTrust Services, LLC — IdenTrust reported improvements to debugging capabilities merged into its configuration management codebase.
- IdenTrust Services, LLC — IdenTrust stated there were no additional updates and the issue was considered closed/resolved on its side.
- Mozilla representative — Mozilla stated it would close the bug on Friday, 18-Oct-2024, unless additional issues were discussed.