← D-TRUST cases
Bugzilla #2007116 Ca Certificate Compliance Incident Self Reported Incident Externally Reported Incident Ccadb Disclosure Issue

D-Trust incident report on CCADB CRL URL disclosure mismatches

ASSIGNED D-TRUST
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns D-Trust’s incident report about four Intermediate CA certificate records in CCADB whose disclosed CRL URLs did not exactly match the CRL URLs encoded in the corresponding certificates, contrary to CCADB Policy 2.0 section 6.2. D-Trust said the issue was triggered by an external Certificate Problem Report received on 2025-12-18, after which it investigated, replied to the reporter, confirmed the mismatch, and corrected the CCADB entries the same day. D-Trust stated that the issue was limited to CCADB disclosure data and that the disclosed URLs still resolved to the applicable CRLs. In the thread, D-Trust refined its root cause analysis to say the problem stemmed from lacking a defined update and revalidation mechanism for variable disclosure data after a policy change, combined with reliance on an indirect data source rather than current certificate data. D-Trust reported remediation including deriving CCADB disclosures from certificate-related sources, completing a policy-update validation control, and implementing an automated reconciliation control that compares CCADB metadata against certificate-related values and generates alerts on deviations. On 2026-07-08, D-Trust added that its original plan to retire a legacy www.d-trust.net CRL endpoint was incomplete because active CA certificates still reference that URI through 2029-11-05, so it updated the plan to keep the endpoint available as an HTTP 301 redirect to crl.d-trust.net until those CA certificates are retired or no longer reference the legacy URI. On 2026-07-24, D-Trust said there was nothing new to report and that it continues to work on the ongoing action items. The bug remains open and assigned.

Model: gpt-5.4 Generated: 2026-06-13 21:33 UTC Revised: 2026-07-26 06:00 UTC Confidence: 0.96 35 comments
Chronology
  1. CCADB Policy Version 2.0 exact-match CRL URL disclosure requirement became effective.
  2. An external Certificate Problem Report triggered D-Trust's investigation into CRL URL disclosures in CCADB.
  3. D-Trust confirmed mismatches affecting four Intermediate CA records, replied to the reporter, and corrected the CCADB entries.
  4. D-Trust reported the problem to its Conformity Assessment Body.
  5. D-Trust reported completion of its policy-update validation action item.
  6. D-Trust described an automated weekly reconciliation mechanism comparing CCADB data with certificate-related values.
  7. D-Trust said Phase 1 of the reconciliation mechanism was complete and Phase 2 was delayed.
  8. D-Trust said the deployed reconciliation control was operational and that API migration work was future maintenance rather than incident remediation.
  9. D-Trust updated its remediation plan to keep the legacy www.d-trust.net CRL endpoint available as an HTTP 301 redirect because active CA certificates still reference that URI until 2029-11-05.
  10. D-Trust said ongoing action items were still being worked.
Thread Activity
  1. D-Trust — D-Trust opened the bug with a preliminary incident report stating that a third party had reported undisclosed or mismatched CRLDP HTTP URLs in CCADB records.
  2. D-Trust — D-Trust filed its full incident report, confirmed four affected Intermediate CA records, and said the CCADB entries had been corrected.
  3. Community commenter — Dean Reed questioned the completeness of the investigation, the earlier no-security-impact wording, and the specificity of D-Trust's action items.
  4. D-Trust — D-Trust replied that additional CRL endpoints did not necessarily all require disclosure, acknowledged the no-security-impact wording was inappropriate, and explained its prior validation approach.
  5. D-Trust — D-Trust said there were no new updates and that a revised incident report would be published shortly.
  6. Google representative — The Chrome Root Program asked for a deeper 5-Why analysis, explanation of multiple CRLDP URIs, clarification of the proposed validation control, and whether linting could be extended to detect this issue.
  7. D-Trust — D-Trust provided a refined 5-Why analysis, explained its use of multiple CRLDP URIs, and said the third-party challenge or validation was part of an existing action item.
  8. D-Trust — D-Trust posted a revised full incident report with updated wording and root cause analysis.
  9. Bdr representative — D-Trust updated an action item to disable www-endpoint CRLDP URLs after the last subscriber certificates from the affected hierarchies are no longer valid.
  10. Community commenter — Malcolm Doody asked when the last subscriber certificate would expire because the action item due date was otherwise unclear.
  11. D-Trust — D-Trust said the relevant roots are valid until 2029-05-11, that replacement roots are being introduced, and that the policy-update validation action item had been completed.
  12. Bdr representative — D-Trust described Phase 1 of an automated weekly CCADB-versus-certificate cross-check and said Phase 2 would target direct API integration.
  13. D-Trust — D-Trust marked several action items completed and left the www-endpoint handling and automated reconciliation implementation items ongoing.
  14. Bdr representative — D-Trust reported that Phase 1 was completed on schedule and that Phase 2 had been delayed to 2026-06-24.
  15. D-Trust — D-Trust requested that the next update deadline be set for 2026-06-12.
  16. D-Trust — D-Trust said implementation of the automated reconciliation mechanism was still in progress and promised another update on 2026-06-19.
  17. D-Trust — D-Trust said the automated reconciliation tool was running in a sandbox environment while production credentials were being worked on.
  18. Bdr representative — D-Trust said the reconciliation control was operational, that Phase 2 API integration had been developed and tested in the sandbox, and that future API changes meant the remaining migration work would be treated as maintenance rather than incident remediation.
  19. D-Trust — D-Trust said there was nothing new to report and that it continues to monitor the ticket.
  20. D-Trust — D-Trust said preparation of the closure report identified that active CA certificates still reference the legacy www.d-trust.net CRL URI, updated the plan to keep that endpoint as an HTTP 301 redirect, marked the automated reconciliation mechanism completed, and said it will publish a closure report after the final remediation activity is finished.
  21. Bdr representative — D-Trust said there was nothing new to report and that it continues to work on the ongoing action items.
  22. D-Trust — D-Trust said there was nothing new to report and that it continues to work on the ongoing action items.
Participants
D-Trust Community commenter Google representative Bdr representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2012511 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2026-01-26 · Closed 2026-04-19 · 94% similar
D-Trust: CRL HTTP Media Type
#2009149 RESOLVED Incident Opened 2026-01-08 · Closed 2026-04-19 · 93% similar
D-Trust: Expired certificate provided on the CA TLS test website for demonstration of valid certificates
#2004699 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Repository Issue Opened 2025-12-08 Still Open · 88% similar
Netlock: CA in AIA in PEM format
#1682270 RESOLVED Ca Certificate Compliance Incident Closure Request Opened 2020-12-14 · Closed 2026-06-12 · 85% similar
D-TRUST: Private Key Disclosed by Customer as Part of CSR
#2010600 RESOLVED Incident Opened 2026-01-15 · Closed 2026-02-27 · 85% similar
D-Trust: CRLs of CAs issuing CA certificates exceed the maximum validity period
#2037000 ASSIGNED Self Reported Incident Certificate Misissuance Problem Reporting Failure Opened 2026-05-05 Still Open · 85% similar
D-Trust: Missing Pre-Sign Linting for S/MIME Issuing CAs
#2004732 RESOLVED Ca Certificate Compliance Incident Opened 2025-12-08 · Closed 2026-01-05 · 85% similar
Certigna: AIA CA issuer field pointing to PEM encoded cert
#1976837 RESOLVED Incident Opened 2025-07-11 · Closed 2025-08-19 · 84% similar
D-Trust: Defective certificate incident reporting form

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action