← DigiCert cases
Bugzilla #2009491 Ca Certificate Compliance Incident Self Reported Incident Repository Issue Policy Document Issue

DigiCert incident report: non-functioning caIssuers AIA URLs returned 404s

RESOLVED FIXED DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

DigiCert opened this case to report an externally identified incident involving non-functioning `caIssuers` AIA URLs in webPKI certificates. The reported URLs returned 404 errors and prevented CA certificate downloads; DigiCert later found a total of 30 affected `caIssuers` AIA URLs across TLS, S/MIME, Authentication, and Timestamp certificates. DigiCert said the root cause was a missed manual step during CA creation, where `.crt` files were not uploaded to the AIA repository server, and that the workflow lacked automation and automated validation. DigiCert republished the affected `.crt` files, verified the URLs, and stated that all action items were completed. The bug was resolved as FIXED, and DigiCert requested closure after posting its closure summary.

Model: gpt-5.4-mini Generated: 2026-06-13 11:48 UTC Revised: 2026-06-22 04:34 UTC Confidence: 0.96 12 comments
Chronology
  1. The earliest affected CA certificate issuance date identified for the non-functioning AIA URLs.
  2. DigiCert identified the incident, republished the affected `.crt` files, and remediated the initially reported non-functioning AIA URLs.
  3. DigiCert verified that the affected AIA URLs were republished and functioning.
  4. DigiCert posted its closure summary and requested closure of the incident report.
Thread Activity
  1. DigiCert — DigiCert filed a full incident report describing two externally reported non-functioning `caIssuers` AIA URLs and later identifying 30 affected URLs in total.
  2. Google representative — Mozilla asked whether DigiCert's investigation was limited to AIA URLs and requested clarification on scope, source-of-truth, and remediation details.
  3. DigiCert — DigiCert clarified its investigation scope, explained its CCADB synchronization process, and said it would raise a policy discussion in the CA/Browser Forum Server Certificate Working Group.
  4. Google representative — Mozilla continued to question the URL mismatch and noted that the referenced URL still appeared to return 404s.
  5. Community commenter — A participant noted that the same CRLDP URL appeared across multiple DigiCert intermediaries and suggested DigiCert may have relied on an internal list.
  6. Sectigo — Rob clarified that the two URLs under discussion differed only by case in the hostname path segment.
  7. DigiCert — DigiCert agreed the two URIs were different, said the active CA URI was functioning, and stated it was on track to complete the action items.
  8. DigiCert — DigiCert said all action items were completed and that it would post a closure summary.
  9. DigiCert — DigiCert posted the closure summary, described the root cause and remediation, and requested closure.
  10. CCADB representative — CCADB issued a final call for comments and said the report would be closed around 2026-02-16.
Participants
DigiCert Google representative Community commenter Sectigo CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2033170 RESOLVED Ca Security Vulnerability Incident Self Reported Incident Revocation Issue Opened 2026-04-18 · Closed 2026-07-20 · 100% similar
DigiCert: Misissued code signing certificates
#1950144 RESOLVED Incident Self Reported Incident Opened 2025-02-24 · Closed 2026-06-11 · 100% similar
DigiCert: Threat of legal action to stifle Bugzilla discourse
#1978163 RESOLVED Self Reported Incident Opened 2025-07-18 · Closed 2025-10-29 · 95% similar
DigiCert: Re-use of WHOIS validation shortly after deadline
#1962829 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Policy Document Issue Opened 2025-04-26 · Closed 2026-04-26 · 94% similar
Microsoft PKI Services: Policy document bug
#1974539 RESOLVED Self Reported Incident Revocation Issue Opened 2025-06-27 · Closed 2025-10-09 · 93% similar
DigiCert: DCV logging issue
#2011314 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Externally Reported Incident Opened 2026-01-19 · Closed 2026-06-23 · 88% similar
Netlock: unspecifed revocation code (0) in CRL
#2021175 RESOLVED Ca Certificate Compliance Incident Opened 2026-03-05 · Closed 2026-04-03 · 87% similar
Microsoft PKI Services: Failure to update action item status within 3 days
#2014610 RESOLVED Self Reported Incident Incident Opened 2026-02-05 · Closed 2026-04-11 · 87% similar
IdenTrust: Root OCSP Signer certificate mis-issuance

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action