← Amazon Trust Services cases
Bugzilla #1914893 Technical Compliance

Amazon Trust Services: CRL not DER-encoded

RESOLVED FIXED Amazon Trust Services
AI Summary

Amazon Trust Services faced an issue where a Certificate Revocation List (CRL) was served in PEM format instead of the required DER format, violating RFC5280. This was due to a recent change to an automated deployment process that did not include checks for CRL format. The issue was identified during a regular review, and corrective actions were taken to ensure compliance. The CRL was updated to the correct format shortly after the issue was discovered, and Amazon Trust Services has since requested the case be closed as resolved.

Model: gpt-4o-mini Generated: 2026-06-13 15:29 UTC Confidence: 1.00
Chronology
  1. Deployed new CRL to the specified URI.
  2. Regular review of CRLWatch identified a parsing error.
  3. Incident identified during the next regular review.
  4. Updated CRL in correct format completed deployment.
  5. Requested closure of the issue as resolved.
Participants
Andrew Ayer Trevoli (Amazon Trust Services) bwilson@mozilla.com
External References
Similar Local Cases
#1746945 RESOLVED Technical Compliance Opened 2021-12-20 · Closed 2023-02-22 · 60% similar
Amazon Trust Services: Missing CAA Check For Test Website Certificates
#1521623 RESOLVED Technical Compliance Opened 2019-01-21 · Closed 2024-05-09 · 57% similar
Amazon Trust Services: Failure to comply with RFC 5280
#1848280 RESOLVED Technical Compliance Opened 2023-08-11 · Closed 2023-10-12 · 48% similar
Microsoft PKI Services: 3-Month Access Review Process Failure
#1848279 RESOLVED Technical Compliance Opened 2023-08-11 · Closed 2023-10-12 · 47% similar
Microsoft PKI Services: Trusted Role Control Failure
#1772644 RESOLVED Technical Compliance Opened 2022-06-04 · Closed 2023-02-22 · 47% similar
Apple: CRL issuance frequency deviates from CPS in some cases
#1830088 RESOLVED Technical Compliance Opened 2023-04-26 · Closed 2024-03-27 · 41% similar
Sectigo: Late termination of privileged access to Certificate Systems
#1428891 RESOLVED Technical Compliance Opened 2018-01-08 · Closed 2023-02-22 · 41% similar
Entrust: Non-BR-Compliant OCSP Responder
#2008027 RESOLVED Technical Compliance Opened 2025-12-30 · Closed 2026-02-09 · 40% similar
PKIoverheid: TSP CIBG Findings in 2025 ETSI Audit - Incident Report #6 – Access Control Management

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action