← D-TRUST cases
Bugzilla #2012511
Certificate Problem Report
D-Trust: CRL HTTP Media Type
RESOLVED
FIXED
D-TRUST
AI Summary
D-Trust was reported for serving Certificate Revocation Lists (CRLs) using the incorrect media type application/x-pkcs7-crl instead of the recommended application/pkix-crl as per RFC 5280. Following an internal review, D-Trust confirmed that there was no valid technical justification for this deviation and updated their configuration accordingly on February 5, 2026. They also integrated CRL Watch monitoring to prevent future occurrences. The incident was resolved with no certificates affected.
Chronology
- External notification received regarding CRL media type
- CRL delivery configuration updated to application/pkix-crl
- Integration of CRL Watch monitoring completed
Participants
Ana Laura Martorano
Enrico Entschew
Pete Cooper
Hablutzel
External References
Similar Local Cases
D-Trust: Expired certificate provided on the CA TLS test website for demonstration of valid certificates
D-Trust: Defective certificate incident reporting form
D-Trust: Missing Pre-Sign Linting for S/MIME Issuing CAs
D-TRUST: Wrong key usage (Key Agreement)
D-Trust: Missing Pre-Signing Linting for TLS Issuance
D-TRUST: incorrectly formatted businessCategory entry
D-TRUST: EV certificates with incorrectly used businessCategory entry
D-TRUST: Wrong key usage (Key Encipherment)