← D-TRUST cases
Bugzilla #2007116
Certificate Problem Report
D-Trust: CRL URL Disclosure
ASSIGNED
D-TRUST
AI Summary
D-Trust GmbH received a Certificate Problem Report indicating that certain CRL URLs in valid certificates did not match the disclosed URLs in the CA Certificate records on CCADB. An internal investigation confirmed discrepancies for four Intermediate CA certificate records, constituting non-compliance with CCADB Policy requirements. The issue was addressed by correcting the CCADB entries. No security impact was observed as the correct CRLs were always reachable, ensuring accurate revocation information for relying parties.
Chronology
- CCADB Policy Version 2.0 entered into force
- D-Trust received a certificate problem report regarding CRL URLs
- Investigation started
- Correction of CRL URL entries in CCADB
- Reported the problem to the Conformity Assessment Body
Participants
Ana Laura Martorano
Dean Reed
External References
Similar Local Cases
D-Trust: Missing Pre-Sign Linting for S/MIME Issuing CAs
D-Trust: Defective certificate incident reporting form
D-Trust: CRLs of CAs issuing CA certificates exceed the maximum validity period
CCADB: Bogus CAA info by D-Trust
D-TRUST: Certificate with RSA key where modulus is not divisible by 8
D-Trust: CRL-Entries without required CRL Reason Code
D-Trust: QCStatement with http link of PKI Disclosure Statements
Netlock: unspecifed revocation code (0) in CRL