eMudhra: Invalid CRL signatures
On June 5, 2025, eMudhra was alerted by Mozilla's monitoring service regarding six Certificate Revocation Lists (CRLs) that were published with invalid ECDSA signatures due to incorrect private key usage. The issue was initially reported by Sectigo via email on June 3, but the message was quarantined and not seen until June 5. eMudhra investigated and confirmed the problem, publishing corrected CRLs on June 6. A full incident report was submitted, detailing the root cause as a manual process error and outlining remediation steps, including transitioning to an automated CRL signing process. All corrective actions were completed by June 20, 2025.
- CRLs generated and published with incorrect key configuration
- Correct CRLs published after validation
- Sectigo — Reported invalid CRL signatures for eMudhra.
- Emudhra representative — Submitted preliminary incident report acknowledging the issue.
- Emudhra representative — Provided full incident report detailing the root cause and remediation.
- Emudhra representative — Confirmed completion of all action items related to the incident.
- Emudhra representative — Requested closure of the incident report.