← TrustAsia Technologies, Inc. cases
Bugzilla #2007072 Repository Issue

TrustAsia: CRL disclosure address in CCADB used HTTPS scheme instead of HTTP (fixed)

RESOLVED FIXED TrustAsia Technologies, Inc.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

TrustAsia received a Certificate Problem Report on 2025-12-19 stating that for the ICA “TrustAsia OV TLS RSA CA 2024”, the CRL URL disclosed in CCADB used the HTTPS scheme while the CRLDP in the certificate used the HTTP scheme. TrustAsia investigated and confirmed the mismatch, which it stated resulted in nonconformity with CCADB Policy v2.0 Section 6.2 requiring URLs to match exactly as they appear in the certificates. TrustAsia corrected the CRL information for the affected ICA in CCADB on the same day it received the report. In its incident report closure summary, TrustAsia also stated it initiated development and deployment of technical validation tools to prevent recurrence, including character-level URL scheme exact matching and other CCADB update validation checks. The bug is marked RESOLVED with resolution FIXED. TrustAsia requested closure after stating all remediation actions were completed and implemented as scheduled.

Model: gpt-5.4-nano Generated: 2026-06-13 20:15 UTC Revised: 2026-06-16 18:13 UTC Confidence: 0.86 7 comments
Chronology
  1. TrustAsia added “TrustAsia OV TLS RSA CA 2024” to CCADB and later peer review corrected some CRL information, but the CRL disclosure for this ICA was inadvertently omitted.
  2. TrustAsia received a Certificate Problem Report about a CRL URL scheme mismatch between CCADB and the certificate, then corrected the CCADB record.
  3. TrustAsia reported completion of action items including adding technical controls for CCADB data accuracy validation.
  4. TrustAsia submitted the report closure summary and requested bug closure.
Thread Activity
  1. TrustAsia Technologies, Inc. — TrustAsia reported a preliminary incident: a third party said the CCADB CRL disclosure used HTTPS while the certificate used HTTP, and TrustAsia said it corrected the CCADB CRL information and would provide a full report by 2025-12-26.
  2. TrustAsia Technologies, Inc. — TrustAsia provided a full incident report, confirming the HTTPS-vs-HTTP mismatch, stating it corrected the CCADB record on the day of receipt, and describing the investigation timeline and contributing factors.
  3. TrustAsia Technologies, Inc. — e**********g@trustasia.com stated they were working on action item #3 and had no other updates.
  4. TrustAsia Technologies, Inc. — C**********l@trustasia.com repeated that they were working on action item #3 with no other updates.
  5. TrustAsia Technologies, Inc. — TrustAsia posted a weekly update showing action items (including modifying the CRL error in CCADB and adding technical validation controls) marked complete and said they were preparing the report closure summary.
  6. TrustAsia Technologies, Inc. — TrustAsia submitted the report closure summary, stating it corrected the CCADB record and implemented technical validation mechanisms, and requested closure.
  7. CCADB representative — i**********g@ccadb.org issued a final call for comments and said the incident report would be closed around 2026-01-23.
Participants
TrustAsia Technologies, Inc. CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2007116 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Externally Reported Incident Opened 2025-12-19 Still Open · 63% similar
D-Trust: CRL URL Disclosure
#2047843 RESOLVED Ca Certificate Compliance Problem Reporting Failure Revocation Issue Opened 2026-06-16 · Closed 2026-07-09 · 60% similar
Certigna: Pre-certificates not recognised by the OCSP responder
#1320943 RESOLVED Revocation Issue Repository Issue Opened 2016-11-29 · Closed 2022-11-14 · 59% similar
Add revoked certificate Certification Authority of WoSign G2 issued by Certum CA root to OneCRL
#2048626 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Repository Issue Opened 2026-06-18 Still Open · 58% similar
Kamu SM: Incorrect CRL Served at SSL CRL Distribution Point
#2049179 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Problem Reporting Failure Opened 2026-06-21 Still Open · 58% similar
CFCA: OCSP Service return unauthorized responses
#1800405 RESOLVED Repository Issue Opened 2022-11-14 · Closed 2023-02-22 · 58% similar
Amazon Trust Services / DigiCert: 404 error when fetching CRL
#1942270 RESOLVED Revocation Issue Repository Issue Opened 2025-01-17 · Closed 2025-04-07 · 57% similar
SSL.com: Revocation process requires submission to a form that is unusable
#708229 RESOLVED Common Ca Database Repository Issue Opened 2011-12-07 · Closed 2022-11-14 · 57% similar
GoDaddy's intermediate CA not in the Mozilla CA bundle

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action