D-Trust: 19 TLS precertificates issued with validity > 200-day maximum (TLS BR 6.3.2)
D-Trust reported that it mis-issued 19 TLS precertificates with validity periods exceeding the 200-day maximum allowed by the TLS Baseline Requirements (Section 6.3.2), as introduced by Ballot SC-81. The issue was identified internally via automated linting checks performed after precertificate issuance and CT submission; the linting detected the non-compliant validity period and blocked issuance of the corresponding final TLS end-entity certificates. D-Trust stated that the pre-certificates were signed by the Issuing CA and submitted to CT logs, and that all affected pre-certificates were revoked on 2026-03-15 15:34 UTC. D-Trust also performed an emergency modification of the affected product configuration to prevent further non-compliant pre-certificates, and later implemented corrective changes in the issuance path by 2026-03-15 21:45 UTC. In the later full incident report, D-Trust described contributing factors including failure to execute/enforce QA verification steps before productive deployment, a deficient approval process that did not verify required pre-deployment QA checks, and a delayed implementation timeline due to compressed deadlines. D-Trust requested closure after completing immediate remediation actions and completing disclosed action items.
- D-Trust issued 19 non-compliant TLS precertificates with validity exceeding the 200-day maximum; automated linting later blocked final certificate issuance and the precertificates were revoked.
- Bdr representative — Opened a preliminary incident report stating D-Trust identified internally that 19 TLS precertificates exceeded the 200-day maximum validity and that all affected precertificates were revoked after identification.
- D-Trust — Submitted a full incident report describing the mis-issuance, stating pre-certificates were CT-logged, final certificates were not issued due to workflow blocking, and that all affected pre-certificates were revoked on 2026-03-15 15:34 UTC.
- D-Trust — Provided additional analysis stating D-Trust stopped all issuance from the affected part of its PKI as of 2026-04-02 08:45 UTC and noted a separate preliminary incident report would be filed for a broader compliance gap.
- Bdr representative — Noted that a new incident report was opened in a separate bug and provided its Bugzilla link.
- Bdr representative — Answered questions about the updated notAfter computation logic and clarified that only validity-period enforcement was changed in the RA system.
- D-Trust — Posted the report closure summary, including remediation (revocation completed by 16:34) and root-cause contributing factors, and requested closure after completing action items.
- CCADB representative — Issued a final call for comments/questions and stated the incident report would be closed approximately 2026-06-01.