← D-TRUST cases
Bugzilla #2009149
Incident
D-Trust: Expired certificate provided on the CA TLS test website for demonstration of valid certificates
RESOLVED
FIXED
D-TRUST
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
D-Trust received a report that a TLS test website was serving an expired certificate. This incident was triggered by a third-party report and was linked to a misinterpretation of policy during a rollover transition, which led to an operational issuance stop. D-Trust restored valid certificates on the test website on January 15, 2026, and implemented a new validation process for policy updates to prevent future occurrences. The incident report was completed and is now resolved.
Chronology
- Expired certificate served on the test website.
- Non-compliance identified after third-party report.
- Valid certificates restored on the test website.
Thread Activity
- D-Trust — Preliminary incident report received regarding expired certificate.
- D-Trust — Full incident report detailing timeline and root cause analysis.
- Bdr representative — Closure report summary provided, detailing remediation and commitments.
Participants
D-Trust
Google representative
Bdr representative
Community commenter
CCADB representative
External References
Similar Local Cases
D-Trust: Defective certificate incident reporting form
D-Trust: CRLs of CAs issuing CA certificates exceed the maximum validity period
D-Trust: CRL URL Disclosure
D-TRUST: Private Key Disclosed by Customer as Part of CSR
D-Trust: Missing Pre-Sign Linting for S/MIME Issuing CAs
DigiCert: Several non-functioning AIA URLs
Certigna: AIA CA issuer field pointing to PEM encoded cert
IdenTrust: Unauthorized OCSP responses for cross-signed roots