D-Trust self-disclosed incident on mismatched CRL URL disclosures in CCADB
This case concerns D-Trust’s incident report about four Intermediate CA certificate records in CCADB whose disclosed CRL URLs did not exactly match the CRL Distribution Point URLs encoded in corresponding certificates, contrary to CCADB Policy 2.0 section 6.2. D-Trust said the issue was triggered by an external Certificate Problem Report received on 2025-12-18, after which it investigated, replied to the reporter, confirmed the mismatch, and corrected the CCADB entries the same day. In the discussion, D-Trust clarified that the issue was limited to CCADB disclosure data and stated that the disclosed URLs still resolved to the applicable CRLs. D-Trust refined its root cause analysis to say that CCADB disclosure data was maintained independently of certificate data and was not reconciled against issued certificates, and that the process for the updated policy did not contain defined control points for updating and validating CA-related disclosure data. Reported remediation included correcting and verifying the affected CCADB records, implementing an automated reconciliation control that compares CCADB disclosure data against certificate inventory and generates alerts, and configuring legacy www.d-trust.net CRL endpoints to return HTTP 301 redirects to corresponding crl.d-trust.net endpoints while those legacy URIs remain referenced by active certificates. On 2026-08-27, D-Trust posted a closure summary, said all disclosed action items had been completed, and requested closure. In that closure summary, D-Trust also said that a third-party report found an additional implementation gap after deployment of the reconciliation control and that this separate issue is being tracked in Bug 2055250. The bug was then given a final call for comments and is now closed as RESOLVED FIXED.
- CCADB Policy Version 2.0 exact-match CRL URL disclosure requirement became effective.
- An external Certificate Problem Report triggered D-Trust's investigation into CRL URL disclosures in CCADB.
- D-Trust confirmed mismatches affecting four Intermediate CA records, replied to the reporter, and corrected the CCADB entries.
- D-Trust reported the problem to its Conformity Assessment Body.
- D-Trust reported completion of its policy-update validation action item.
- D-Trust described an automated weekly reconciliation mechanism comparing CCADB data with certificate-related values.
- D-Trust said Phase 1 of the reconciliation mechanism was complete and Phase 2 was delayed.
- D-Trust said the deployed reconciliation control was operational and that API migration work was future maintenance rather than incident remediation.
- D-Trust updated its remediation plan to keep the legacy www.d-trust.net CRL endpoint available as an HTTP 301 redirect because active CA certificates still reference that URI until 2029-11-05.
- D-Trust reported completion of the HTTP 301 redirect action item for the legacy CRL endpoint.
- D-Trust posted a closure summary, said all disclosed action items were complete, and requested closure while noting a separate additional implementation gap is tracked in Bug 2055250.
- The incident report was closed as RESOLVED FIXED after the final call period.
- D-Trust — D-Trust opened the bug with a preliminary incident report stating that a third party had reported undisclosed or mismatched CRLDP HTTP URLs in CCADB records.
- D-Trust — D-Trust filed its full incident report, confirmed four affected Intermediate CA records, and said the CCADB entries had been corrected.
- Community commenter — Dean Reed questioned the completeness of the investigation, the earlier no-security-impact wording, and the specificity of D-Trust's action items.
- D-Trust — D-Trust replied that additional CRL endpoints did not necessarily all require disclosure, acknowledged the no-security-impact wording was inappropriate, and explained its prior validation approach.
- D-Trust — D-Trust said there were no new updates and that a revised incident report would be published shortly.
- Google representative — The Chrome Root Program asked for a deeper 5-Why analysis, explanation of multiple CRLDP URIs, clarification of the proposed validation control, and whether linting could be extended to detect this issue.
- D-Trust — D-Trust provided a refined 5-Why analysis, explained its use of multiple CRLDP URIs, and said the third-party challenge or validation was part of an existing action item.
- D-Trust — D-Trust posted a revised full incident report with updated wording and root cause analysis.
- Bdr representative — D-Trust updated an action item to disable www-endpoint CRLDP URLs after the last subscriber certificates from the affected hierarchies are no longer valid.
- Community commenter — Malcolm Doody asked when the last subscriber certificate would expire because the action item due date was otherwise unclear.
- D-Trust — D-Trust said the relevant roots are valid until 2029-05-11, that replacement roots are being introduced, and that the policy-update validation action item had been completed.
- Bdr representative — D-Trust described Phase 1 of an automated weekly CCADB-versus-certificate cross-check and said Phase 2 would target direct API integration.
- D-Trust — D-Trust marked several action items completed and left the www-endpoint handling and automated reconciliation implementation items ongoing.
- Bdr representative — D-Trust reported that Phase 1 was completed on schedule and that Phase 2 had been delayed to 2026-06-24.
- D-Trust — D-Trust requested that the next update deadline be set for 2026-06-12.
- D-Trust — D-Trust said implementation of the automated reconciliation mechanism was still in progress and promised another update on 2026-06-19.
- D-Trust — D-Trust said the automated reconciliation tool was running in a sandbox environment while production credentials were being worked on.
- Bdr representative — D-Trust said the reconciliation control was operational, that Phase 2 API integration had been developed and tested in the sandbox, and that future API changes meant the remaining migration work would be treated as maintenance rather than incident remediation.
- D-Trust — D-Trust said there was nothing new to report and that it continues to monitor the ticket.
- D-Trust — D-Trust said preparation of the closure report identified that active CA certificates still reference the legacy www.d-trust.net CRL URI, updated the plan to keep that endpoint as an HTTP 301 redirect, marked the automated reconciliation mechanism completed, and said it will publish a closure report after the final remediation activity is finished.
- Bdr representative — D-Trust said there was nothing new to report and that it continues to work on the ongoing action items.
- D-Trust — D-Trust said there was nothing new to report and that it continues to work on the ongoing action items.
- D-Trust — D-Trust reported that the action item to set up an HTTP 301 redirect to crl.d-trust.net had been completed.
- D-Trust — D-Trust said it is preparing the closure report for this incident and continues to monitor the ticket.
- Bdr representative — D-Trust said all action items in this report were complete, but it would revise the Full Incident Report in Bug 2055250 before requesting closure of this bug.
- D-Trust — D-Trust repeated that it would request closure after revising the Full Incident Report in Bug 2055250.
- D-Trust — D-Trust posted a closure summary, said all disclosed action items were complete, noted a separate additional implementation gap is tracked in Bug 2055250, and requested closure.
- CCADB representative — CCADB incident reporting issued a final call for comments or questions and said the bug would otherwise be closed on approximately 2026-09-03.
- The bug status changed to RESOLVED with resolution FIXED.