← Amazon Trust Services cases
Bugzilla #2009525
Certificate Problem Report
Amazon Trust Services: Additional CRL Characteristics Desired in CP/CPS
RESOLVED
FIXED
Amazon Trust Services
AI Summary
Amazon Trust Services (ATS) addressed a disclosure regarding the backdating of 'thisUpdate' timestamps in their Certificate Revocation Lists (CRLs). The issue arose when a third party inquired about the clarity of ATS's Certificate Policy (CP) and Certification Practice Statement (CPS) concerning CRL behavior. ATS confirmed that backdating is a common practice to accommodate clock skew, and they committed to updating their CP/CPS to provide clearer guidelines. The incident was resolved with the completion of the necessary updates by March 6, 2026.
Chronology
- ATS begins publishing backdated CRLs.
- ATS receives inquiry about CRLs.
- ATS updates CP/CPS with additional clarity.
- Final updates to CP/CPS completed.
Participants
Aaron Poulsen (Amazon Trust Services)
Trevor Lip (Amazon Trust Services)
Mozilla
Apple
Google
External References
Similar Local Cases
DigiCert: DCV logging issue
Amazon Trust Services: Revocation Time for Intermediate Certificates
Amazon Trust Services / DigiCert: 404 error when fetching CRL
Amazon Trust Services: Test revoked certificates with invalid validity period
Amazon Trust Services: Revoked Sample Certs - No SANs
DigiCert: inconsistent revocation / OCSP / CRL behavior
DigiCert: Re-use of WHOIS validation shortly after deadline
Amazon Trust Services / DigiCert: 404 error when fetching CRL