Telia: Incorrect CRL URL on Telia RSA Signing Root CA v3 record in CCADB
This case reports an incorrect CRL URL in a CCADB Root CA record for Telia RSA Signing Root CA v3 (CCADB ID: A012100). The issue was identified after a third party notified Telia’s CA general/support email (cainfo@teli) about an issue detected by a newly introduced CRL Watch tool. Telia determined that the CCADB record contained an incorrect URL in the “Full CRL Issued By This CA” field, which was a violation of CCADB Policy v2.0 section 6.2. Telia corrected the CCADB Root record by creating an Add/Change Root Record case to update the CRL distribution point URL. Telia also reported completed action items, including proposing CRL verification functionality in the CCADB CA record update UI and extending a “four eyes principle” practice for verifying CA record updates. The bug is marked RESOLVED with resolution FIXED, and Telia requested closure of the incident report after remediation and completed commitments.
- Telia submitted a Root CA record for Telia RSA Signing Root CA v3 to CCADB with an incorrect CRL URL.
- Telia identified the incorrect CRL URL in the CCADB record and updated the CCADB Root record to correct the CRL distribution point URL.
- Telia submitted a report closure summary and requested closure after completing remediation and action items.
- Teliacompany representative — Filed a full incident report stating the CCADB Root CA record for Telia RSA Signing Root CA v3 had an incorrect CRL URL in the “Full CRL Issued By This CA” field and described the timeline, impact as N/A, and root causes.
- Teliacompany representative — Reported completion of an action item by sending a proposal to CCADB support email to implement CRL verification in the CCADB update UI.
- Teliacompany representative — Provided a weekly update that the pending action item was progressing as expected.
- Teliacompany representative — Reported completion of a “four eyes principle” action item by amending the CCADB update checklist and making changes effective for Telia CA PKI Team.
- Teliacompany representative — Submitted the report closure summary, stating remediation was done in CCADB and requesting closure after action items were completed.
- CCADB representative — Posted a final call for comments and noted the incident report would be closed on approximately 2026-02-25 if no questions were raised.