D-Trust: CRLs of CAs issuing CA certificates exceed the maximum validity period
D-Trust reported a compliance issue regarding the validity period of Certificate Revocation Lists (CRLs) for CAs issuing CA certificates, which exceeded the maximum permitted validity period by approximately one day. The issue was identified following a third-party report, and D-Trust confirmed that the CRLs were operationally republished but did not comply with the CA/Browser Forum TLS Baseline Requirements. The non-compliance was addressed by correcting the CRL profile and implementing automated linting to prevent future occurrences. The incident was resolved on January 15, 2026, with all action items completed and monitoring measures put in place.
- Non-compliance started when CRLs were issued exceeding the maximum CRL validity period.
- Non-compliance identified following a third-party report.
- First corrected CRL produced and published, resolving the non-compliance.
- D-Trust — Preliminary Incident Report submitted regarding CRLs exceeding validity period.
- D-Trust — Full Incident Report provided detailing the non-compliance and its timeline.
- D-Trust — Report Closure Summary issued, confirming completion of action items and resolution.