← DigiCert cases
Bugzilla #2007219
Certificate Problem Report
DigiCert: Some certificates issued with CRLDPs that don’t exactly match CCADB disclosures
RESOLVED
DigiCert
AI Summary
DigiCert reported an incident involving a small number of issued certificates with CRLDP URLs that did not match those disclosed in the Common CA Database (CCADB). Initial reports indicated four mismatched URLs, but further investigation revealed 334 affected URLs. The issue arose from changes to the CCADB API that disrupted automated CRL synchronization, leading to reliance on manual updates. The discrepancies were resolved, and measures have been implemented to prevent future occurrences.
Chronology
- Preliminary incident report filed
- Full incident report submitted
- Issue resolved
- Automated CRLDP updates restored
- Final call for comments on incident report
Participants
DigiCert
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
DigiCert: DCV logging issue
DigiCert: Subject Serial Numbers for Non-Commercial Entities
DigiCert: Several non-functioning AIA URLs
DigiCert: Re-use of WHOIS validation shortly after deadline
DigiCert: inconsistent revocation / OCSP / CRL behavior
DigiCert: Issuance of certs with weak keys (ROCA)
DigiCert: Encoded HTML entities in attribute values
DigiCert: Issuance of Cert with Compromised Key