← D-TRUST cases
Bugzilla #2012511
Ca Certificate Compliance
Self Reported Incident
D-Trust: CRL HTTP Media Type
RESOLVED
FIXED
D-TRUST
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
D-Trust disclosed an incident regarding its CRL distribution endpoints serving CRLs with the media type application/x-pkcs7-crl instead of the recommended application/pkix-crl as per RFC 5280. This issue was identified following an external report on January 23, 2026, and after an internal review, D-Trust found no justification for the deviation. The configuration was updated to comply with RFC 5280 on February 5, 2026. Additionally, D-Trust integrated CRL Watch monitoring into its internal alerting system by February 12, 2026. The incident was resolved and the case is now closed.
Chronology
- External notification received regarding CRL media type compliance.
- CRL delivery configuration updated to application/pkix-crl.
- Integration of CRL Watch monitoring completed.
Thread Activity
- D-Trust — D-Trust received an external report about CRL media type compliance.
- D-Trust — Full incident report detailing the issue and actions taken was provided.
- Bdr representative — Clarified that the integration of CRL Watch monitoring was completed ahead of schedule.
- Bdr representative — D-Trust is preparing the closure report for the incident.
Participants
D-Trust
Community commenter
Cooperjr representative
Bdr representative
Cabbage representative
CCADB representative
External References
Similar Local Cases
D-Trust: CRL URL Disclosure
D-Trust: Missed Revocation of TLS certificates affected by Bugzilla 1884714
D-TRUST: Issuance of non-conformant SSL certificate
D-TRUST: CRL not DER-encoded
D-TRUST: Precertificate OU > 64 Characters
D-TRUST: Wrong key usage (Key Encipherment)
D-TRUST: Private Key Disclosed by Customer as Part of CSR
D-TRUST: Wrong key usage (Key Agreement)