← certSIGN cases
Bugzilla #2047866 Ccadb Disclosure Issue Incident Repository Issue

certSIGN: incorrect CRL URL added in CCADB during cross-certificate update

ASSIGNED certSIGN
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case reports an incident involving certSIGN’s CCADB data. The certSIGN operator updated the data of a cross-certificate in CCADB and an incorrect URI was added in the CRL path field. certSIGN states that the error was corrected immediately after the incorrect URI was added, and that the cross-certificate was for a “TO BE replacement” on a dedicated PKI system. certSIGN also states that no certificates were affected because the cross-certificate was created for a time when the new PKI system would be included in browsers. The incident was disclosed as part of certSIGN’s root cause analysis of another incident (Bug 2046230) and via an email from Ophelia Pague on 2026-06-11. The reported contributing factors include lack of automated validation tooling in CCADB and missing operator validation/double-checking; the CCADB record was manually corrected on 2026-06-11 05:30.

Model: gpt-5.4-nano Generated: 2026-06-19 19:25 UTC Confidence: 0.82 2 comments
Chronology
  1. certSIGN updated CCADB cross-certificate data and an incorrect CRL URI was entered.
  2. certSIGN corrected the CCADB CRL URI after identifying the issue and reported the incident.
Thread Activity
  1. gabriel.petcu@certsign.ro — Opened the bug with a preliminary incident report stating an incorrect CRL path URI was added during a CCADB cross-certificate update and then corrected immediately.
  2. gabriel.petcu@certsign.ro — Provided a full incident report with timeline, impact statement (no certificates affected), and root cause analysis details (lack of CCADB validation tooling and missing operator double-check).
Participants
gabriel.petcu@certsign.ro Ophelia Pague
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#2049012 UNCONFIRMED Ccadb Disclosure Issue Incident Ccadb Bug Opened 2026-06-19 Still Open · 70% similar
FNMT: Inaccuracy in CRL URL in CCADB
#2007098 RESOLVED Repository Issue Opened 2025-12-19 · Closed 2026-02-12 · 60% similar
GlobalSign: misalignment of CRL URL in CCADB with issued certificates
#2012934 RESOLVED Ccadb Metadata Update Repository Issue Opened 2026-01-28 · Closed 2026-02-26 · 60% similar
Telia: Inccorrect CRL URL on a Root CA record in CCADB
#2031164 RESOLVED Ca Certificate Compliance Ccadb Metadata Update Incident Opened 2026-04-12 · Closed 2026-05-29 · 60% similar
Google Trust Services: Incomplete CRL Distribution Point URLs in CCADB for GTS Roots
#2007066 RESOLVED Ccadb Metadata Update Repository Issue Opened 2025-12-19 · Closed 2026-01-20 · 60% similar
Disig: Missing CA Disig R2I2 Certification Service Full CRL URLs in CCADB
#1777341 RESOLVED Common Ca Database Repository Issue Opened 2022-06-29 · Closed 2022-11-14 · 59% similar
QuoVadis: "unexpired but revoked" constrained CAs unable to be reported in CCADB
#2025597 RESOLVED Incident Opened 2026-03-23 · Closed 2026-05-18 · 59% similar
IdenTrust: Delay in updating a Bug 2016585 - Next update
#1567061 RESOLVED Self Reported Incident Repository Issue Opened 2019-07-18 · Closed 2023-02-22 · 59% similar
GoDaddy: inconsistent disclosure of externally-operated intermediate

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action