DigiCert incident report: non-functioning caIssuers AIA URLs returned 404s
DigiCert opened this case to report an externally identified incident involving non-functioning `caIssuers` AIA URLs in webPKI certificates. The reported URLs returned 404 errors and prevented CA certificate downloads; DigiCert later found a total of 30 affected `caIssuers` AIA URLs across TLS, S/MIME, Authentication, and Timestamp certificates. DigiCert said the root cause was a missed manual step during CA creation, where `.crt` files were not uploaded to the AIA repository server, and that the workflow lacked automation and automated validation. DigiCert republished the affected `.crt` files, verified the URLs, and stated that all action items were completed. The bug was resolved as FIXED, and DigiCert requested closure after posting its closure summary.
- The earliest affected CA certificate issuance date identified for the non-functioning AIA URLs.
- DigiCert identified the incident, republished the affected `.crt` files, and remediated the initially reported non-functioning AIA URLs.
- DigiCert verified that the affected AIA URLs were republished and functioning.
- DigiCert posted its closure summary and requested closure of the incident report.
- DigiCert — DigiCert filed a full incident report describing two externally reported non-functioning `caIssuers` AIA URLs and later identifying 30 affected URLs in total.
- Google representative — Mozilla asked whether DigiCert's investigation was limited to AIA URLs and requested clarification on scope, source-of-truth, and remediation details.
- DigiCert — DigiCert clarified its investigation scope, explained its CCADB synchronization process, and said it would raise a policy discussion in the CA/Browser Forum Server Certificate Working Group.
- Google representative — Mozilla continued to question the URL mismatch and noted that the referenced URL still appeared to return 404s.
- Community commenter — A participant noted that the same CRLDP URL appeared across multiple DigiCert intermediaries and suggested DigiCert may have relied on an internal list.
- Sectigo — Rob clarified that the two URLs under discussion differed only by case in the hostname path segment.
- DigiCert — DigiCert agreed the two URIs were different, said the active CA URI was functioning, and stated it was on track to complete the action items.
- DigiCert — DigiCert said all action items were completed and that it would post a closure summary.
- DigiCert — DigiCert posted the closure summary, described the root cause and remediation, and requested closure.
- CCADB representative — CCADB issued a final call for comments and said the report would be closed around 2026-02-16.