GlobalSign: Inaccurate HTTP caching headers for a subset of CRLs (Atlas platform)
GlobalSign reported that it received an external report indicating its CRL distribution points returned inaccurate HTTP caching headers for a subset of CRLs. In its incident report, GlobalSign stated that for CRLs published through its Atlas platform, the HTTP caching headers (Expires, Last-Modified, and ETag) were inaccurate between 2024-08-22 13:38 and 2024-09-13 15:10. GlobalSign said fresh CRLs were generated, published, and served, but a fault in the update process prevented the corresponding HTTP caching header values from being properly updated, resulting in incorrect (expired) caching headers for CRLs for 185 CAs. GlobalSign identified the root cause as stale configuration files due to a bug in the update process, where after an operating system upgrade the server reload command did not execute as expected and the new header settings were not loaded into memory. GlobalSign updated the configuration of both CRL servers with correct HTTP headers and updated scripts for publishing CRLs and reloading the configuration. It also extended monitoring to cover HTTP headers and completed updates to the QA process to ensure coverage of HTTP header responses and configuration reload behavior; the bug is resolved as FIXED.
- GlobalSign began publishing CRLs with incorrect (expired) HTTP caching header values on its Atlas platform.
- GlobalSign received a report about the CRL caching header issue and identified the root cause.
- GlobalSign updated CRL server configuration to correct HTTP caching headers and resolved the issue.
- GlobalSign extended monitoring to include correctness of HTTP headers.
- GlobalSign completed QA process updates for HTTP header responses and configuration reload behavior.
- GlobalSign nv-sa — GlobalSign said it received a report that its CRL distribution points returned inaccurate caching headers for a subset of CRLs and would provide an incident report no later than 2024-09-24.
- GlobalSign nv-sa — GlobalSign posted an incident report describing the affected Atlas CRLs, impact, timeline, root cause, and action items including script updates, monitoring changes, and QA improvements.
- GlobalSign nv-sa — GlobalSign stated there were no scheduled deliverables that week and that it was on track to deliver remaining actions.
- GlobalSign nv-sa — GlobalSign reported completion of QA process updates for HTTP header responses and configuration reload behavior and said remedial activities were concluded.
- Mozilla representative — Mozilla indicated it would close the bug on 2024-10-18 unless there were still issues to discuss.