← D-TRUST cases
Bugzilla #2010600 Certificate Problem Report

D-Trust: CRLs of CAs issuing CA certificates exceed the maximum validity period

RESOLVED FIXED D-TRUST
AI Summary

D-Trust published a set of CRLs for CAs issuing CA certificates with a nextUpdate value that exceeded the maximum permitted validity period by approximately one day. This non-compliance was identified through a third-party report and was corrected promptly. The root cause was attributed to incomplete compliance controls that focused on the CRL replacement cycle rather than the encoded validity fields. Remedial actions included correcting the CRL profile and extending automated linting to ensure future compliance.

Model: gpt-4o-mini Generated: 2026-06-13 21:34 UTC Confidence: 0.90
Chronology
  1. Non-compliance start date due to CRLs exceeding maximum validity period.
  2. Non-compliance identified through third-party report.
  3. First corrected CRL produced and published.
Participants
Ana Laura Martorano
External References
Similar Local Cases
#2037000 ASSIGNED Certificate Problem Report Opened 2026-05-05 Still Open · 56% similar
D-Trust: Missing Pre-Sign Linting for S/MIME Issuing CAs
#2007116 ASSIGNED Certificate Problem Report Opened 2025-12-19 Still Open · 56% similar
D-Trust: CRL URL Disclosure
#2009149 RESOLVED Certificate Problem Report Opened 2026-01-08 · Closed 2026-04-19 · 56% similar
D-Trust: Expired certificate provided on the CA TLS test website for demonstration of valid certificates
#1976837 RESOLVED Certificate Problem Report Opened 2025-07-11 · Closed 2025-08-19 · 55% similar
D-Trust: Defective certificate incident reporting form
#1563772 RESOLVED Certificate Problem Report Opened 2019-07-05 · Closed 2023-02-22 · 49% similar
D-TRUST: Precertificate OU > 64 Characters
#1610303 RESOLVED Certificate Problem Report Opened 2020-01-20 · Closed 2023-02-22 · 49% similar
D-TRUST: Issuance of non-conformant SSL certificate
#1691117 RESOLVED Certificate Problem Report Opened 2021-02-05 · Closed 2023-02-22 · 49% similar
D-TRUST: Certificate with RSA key where modulus is not divisible by 8
#1879529 RESOLVED Certificate Problem Report Opened 2024-02-09 · Closed 2024-04-06 · 48% similar
D-Trust: "unknown" OCSP response for issued certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action