← D-TRUST cases
Bugzilla #2023458
Certificate Problem Report
D-Trust: TLS Precertificates Exceeding the Maximum Validity Period Allowed by the TLS Baseline Requirements
RESOLVED
FIXED
D-TRUST
AI Summary
D-Trust identified that 19 TLS precertificates were issued with a validity period exceeding the maximum allowed validity of 200 days as defined in the TLS Baseline Requirements. The issue was detected internally during automated linting checks, and all affected precertificates were revoked promptly after identification. The incident was classified as a compliance violation under the CA/Browser Forum Baseline Requirements. D-Trust has committed to addressing procedural failures in their QA deployment and approval processes to prevent recurrence.
Chronology
- Non-compliance identified and affected precertificates revoked.
- Bugzilla incident 2023458 opened.
- Final call for comments on the incident report.
Participants
Enrico Entschew
Dimitris Zacharopoulos
Rob
Ben Wilson
Moritz Schaal
Andrew Ayer
Frank Meissen
External References
Similar Local Cases
D-Trust: Missing Pre-Signing Linting for TLS Issuance
D-Trust: QCStatement with http link of PKI Disclosure Statements
D-Trust: "unknown" OCSP response for issued certificates
e-commerce monitoring GmbH: SCT in precertificate
D-TRUST: Certificate with RSA key where modulus is not divisible by 8
D-TRUST: incorrectly formatted businessCategory entry
D-Trust: LDAP-URL in Subscriber Certificate Authority Information Access field
D-Trust: Missing Pre-Sign Linting for S/MIME Issuing CAs