← D-TRUST cases
Bugzilla #2010600 Incident

D-Trust: CRLs of CAs issuing CA certificates exceed the maximum validity period

RESOLVED FIXED D-TRUST
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

D-Trust reported a compliance issue regarding the validity period of Certificate Revocation Lists (CRLs) for CAs issuing CA certificates, which exceeded the maximum permitted validity period by approximately one day. The issue was identified following a third-party report, and D-Trust confirmed that the CRLs were operationally republished but did not comply with the CA/Browser Forum TLS Baseline Requirements. The non-compliance was addressed by correcting the CRL profile and implementing automated linting to prevent future occurrences. The incident was resolved on January 15, 2026, with all action items completed and monitoring measures put in place.

Model: gpt-4o-mini Generated: 2026-06-13 21:34 UTC Revised: 2026-06-16 18:48 UTC Confidence: 0.85 12 comments
Chronology
  1. Non-compliance started when CRLs were issued exceeding the maximum CRL validity period.
  2. Non-compliance identified following a third-party report.
  3. First corrected CRL produced and published, resolving the non-compliance.
Thread Activity
  1. D-Trust — Preliminary Incident Report submitted regarding CRLs exceeding validity period.
  2. D-Trust — Full Incident Report provided detailing the non-compliance and its timeline.
  3. D-Trust — Report Closure Summary issued, confirming completion of action items and resolution.
Participants
D-Trust Fastly representative Bdr representative CCADB representative
External References
Similar Local Cases
#1976837 RESOLVED Incident Opened 2025-07-11 · Closed 2025-08-19 · 100% similar
D-Trust: Defective certificate incident reporting form
#2009149 RESOLVED Incident Opened 2026-01-08 · Closed 2026-04-19 · 100% similar
D-Trust: Expired certificate provided on the CA TLS test website for demonstration of valid certificates
#2037000 ASSIGNED Self Reported Incident Certificate Misissuance Problem Reporting Failure Opened 2026-05-05 Still Open · 87% similar
D-Trust: Missing Pre-Sign Linting for S/MIME Issuing CAs
#1682270 RESOLVED Ca Certificate Compliance Incident Closure Request Opened 2020-12-14 · Closed 2026-06-12 · 86% similar
D-TRUST: Private Key Disclosed by Customer as Part of CSR
#2007116 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Externally Reported Incident Opened 2025-12-19 Still Open · 85% similar
D-Trust: CRL URL Disclosure
#1963663 RESOLVED Incident Certificate Misissuance Opened 2025-04-30 · Closed 2025-06-12 · 75% similar
Certigna: Multiple Reserved Certificate Policy Identifiers in CA certificates
#1938167 RESOLVED Incident Opened 2024-12-18 · Closed 2025-06-10 · 71% similar
NETLOCK: CRL not published in DER Encoded Format
#1390991 RESOLVED Ca Certificate Compliance Incident Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 71% similar
Disig: Non-BR-Compliant Certificate Issuance

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action