D-Trust: Missed Revocation of TLS certificates affected by Bugzilla 1884714
D-Trust issued TLS certificates containing an LDAP-URL in the Subscriber Certificate Authority Information Access field after September 15, 2023. Upon discovering this issue, D-Trust revoked 2,601 affected certificates within the required timeframe. However, four additional certificates with non-compliant AIA entries were later identified and revoked by October 15, 2024. The root cause was attributed to connection issues between the Nexus CM and CSM, which were not detected during testing. D-Trust has since implemented processes to prevent future occurrences, including an error-tolerant data synchronization system and improved logging practices.
- Entry into force of the provisions from Ballot SC62
- Revocation of 2,601 affected TLS certificates
- Revocation of 4 additional affected certificates
- Bdr representative — Preliminary report detailing the incident and initial actions taken.
- Bdr representative — Final report published with detailed timeline and root cause analysis.
- CCADB representative — Final call for comments or questions on the Incident Report.