TrustAsia: CRL disclosure address in CCADB used HTTPS scheme instead of HTTP (fixed)
TrustAsia received a Certificate Problem Report on 2025-12-19 stating that for the ICA “TrustAsia OV TLS RSA CA 2024”, the CRL URL disclosed in CCADB used the HTTPS scheme while the CRLDP in the certificate used the HTTP scheme. TrustAsia investigated and confirmed the mismatch, which it stated resulted in nonconformity with CCADB Policy v2.0 Section 6.2 requiring URLs to match exactly as they appear in the certificates. TrustAsia corrected the CRL information for the affected ICA in CCADB on the same day it received the report. In its incident report closure summary, TrustAsia also stated it initiated development and deployment of technical validation tools to prevent recurrence, including character-level URL scheme exact matching and other CCADB update validation checks. The bug is marked RESOLVED with resolution FIXED. TrustAsia requested closure after stating all remediation actions were completed and implemented as scheduled.
- TrustAsia added “TrustAsia OV TLS RSA CA 2024” to CCADB and later peer review corrected some CRL information, but the CRL disclosure for this ICA was inadvertently omitted.
- TrustAsia received a Certificate Problem Report about a CRL URL scheme mismatch between CCADB and the certificate, then corrected the CCADB record.
- TrustAsia reported completion of action items including adding technical controls for CCADB data accuracy validation.
- TrustAsia submitted the report closure summary and requested bug closure.
- TrustAsia Technologies, Inc. — TrustAsia reported a preliminary incident: a third party said the CCADB CRL disclosure used HTTPS while the certificate used HTTP, and TrustAsia said it corrected the CCADB CRL information and would provide a full report by 2025-12-26.
- TrustAsia Technologies, Inc. — TrustAsia provided a full incident report, confirming the HTTPS-vs-HTTP mismatch, stating it corrected the CCADB record on the day of receipt, and describing the investigation timeline and contributing factors.
- TrustAsia Technologies, Inc. — e**********g@trustasia.com stated they were working on action item #3 and had no other updates.
- TrustAsia Technologies, Inc. — C**********l@trustasia.com repeated that they were working on action item #3 with no other updates.
- TrustAsia Technologies, Inc. — TrustAsia posted a weekly update showing action items (including modifying the CRL error in CCADB and adding technical validation controls) marked complete and said they were preparing the report closure summary.
- TrustAsia Technologies, Inc. — TrustAsia submitted the report closure summary, stating it corrected the CCADB record and implemented technical validation mechanisms, and requested closure.
- CCADB representative — i**********g@ccadb.org issued a final call for comments and said the incident report would be closed around 2026-01-23.