← Government of Turkey, Kamu Sertifikasyon Merkezi (Kamu SM) cases
Bugzilla #2048626 Ca Certificate Compliance Incident Self Reported Incident Repository Issue Problem Reporting Failure

Kamu SM: Incorrect CRL served at SSL CRL distribution point; final call issued for closure

ASSIGNED Government of Turkey, Kamu Sertifikasyon Merkezi (Kamu SM)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Kamu Sertifikasyon Merkezi (Kamu SM) reported a CRL publication incident affecting its production SSL CRL distribution point at http://depo.kamusm.gov.tr/ssl/SSLSIL.S3.crl. The incident began on 2026-06-17 during a key rollover for the Mobile Qualified Electronic Certificate subordinate CA, when a manual configuration change in the CRL copy service caused an unintended CRL to be served. Kamu SM said the issue was detected by CRLWatch and reported by a community member, and that it corrected the configuration and restored the proper CRL on 2026-06-18 at 06:00 UTC. In its closure update, Kamu SM stated that no certificates were revoked or issued during the incident window and that all action items were completed, including peer review for manual CRL path changes and Nagios CRL integrity monitoring. The latest thread activity is a final call for comments from CCADB incident-reporting, which says the report will be closed on approximately 2026-08-03 if there are no further questions. The case remains ASSIGNED.

Model: gpt-5.4-mini Generated: 2026-06-19 19:38 UTC Revised: 2026-08-02 07:01 UTC Confidence: 0.97 8 comments
Chronology
  1. A key rollover for the Mobile Qualified Electronic Certificate subordinate CA caused an incorrect CRL to be served at the production SSL CRL distribution point.
  2. Kamu SM restored the correct CRL at the production distribution point.
  3. Kamu SM completed the Nagios CRL integrity monitoring action item and stated that all action items were complete.
Thread Activity
  1. Tubitak representative — Posted a preliminary incident report describing the CRL copy service configuration error and noting that the source of disclosure was a third-party report.
  2. Tubitak representative — Posted the full incident report with the timeline, impact, and remediation details, and attached SSL_CRL.zip.
  3. Tubitak representative — Requested a next update of 2026-07-20 while working on an action item.
  4. Tubitak representative — Reported no changes and again requested a next update of 2026-07-20.
  5. Tubitak representative — Reported no changes and said the action item was expected to be finalized and closed by 2026-07-20.
  6. Tubitak representative — Stated that the Nagios CRL integrity monitoring action item was completed, that all action items were complete, and requested closure of the incident report.
  7. CCADB representative — Issued a final call for comments or questions and said the incident report would be closed on approximately 2026-08-03.
Participants
Tubitak representative CCADB representative
Similar Local Cases
#2052399 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Repository Issue Opened 2026-07-03 Still Open · 82% similar
Certainly: Expired certificates on "Valid" and "Revoked" test websites
#2048444 ASSIGNED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Revocation Issue Opened 2026-06-18 Still Open · 81% similar
IdenTrust: End Entity TLS certificate mis-issuance against CP/CPS (IdenTrust certificate policy OIDs)
#2048370 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Revocation Issue Opened 2026-06-17 Still Open · 80% similar
Sectigo: Delay in some OCSP response signing due to application restart loop
#2017845 RESOLVED Certificate Misissuance Self Reported Incident Problem Reporting Failure Opened 2026-02-19 · Closed 2026-07-28 · 80% similar
HARICA: Incorrect nCAId in PSD2 QCStatement for QWACs
#2033412 RESOLVED Ca Certificate Compliance Externally Reported Incident Incident Certificate Misissuance Opened 2026-04-20 · Closed 2026-06-25 · 80% similar
CFCA: CRL signatureAlgorithm Missing NULL Parameter (RFC 4055 Section 5)
#2014590 RESOLVED Self Reported Incident Incident Opened 2026-02-04 · Closed 2026-04-23 · 79% similar
IdenTrust: Unauthorized OCSP responses for cross-signed roots
#2025595 RESOLVED Self Reported Incident Incident Opened 2026-03-23 · Closed 2026-05-18 · 79% similar
IdenTrust: Delay in updating a Bug 2014609 - Next update
#2025596 RESOLVED Self Reported Incident Incident Opened 2026-03-23 · Closed 2026-05-18 · 79% similar
IdenTrust: Delay in updating a Bugzilla ticket Bug 2014610 - Next update

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action