← Government of Turkey, Kamu Sertifikasyon Merkezi (Kamu SM) cases
Bugzilla #2048626 Ca Certificate Compliance Incident Self Reported Incident Repository Issue Problem Reporting Failure

Kamu SM: Incorrect CRL served at SSL CRL distribution point; incident report closed after final call

RESOLVED FIXED Government of Turkey, Kamu Sertifikasyon Merkezi (Kamu SM)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Kamu Sertifikasyon Merkezi (Kamu SM) reported a CRL publication incident affecting its production SSL CRL distribution point at http://depo.kamusm.gov.tr/ssl/SSLSIL.S3.crl. The incident began on 2026-06-17 during a key rollover for the Mobile Qualified Electronic Certificate subordinate CA, when a manual configuration change in the CRL copy service caused an unintended CRL to be served. Kamu SM said the issue was detected by CRLWatch and reported by a community member, and that it corrected the configuration and restored the proper CRL on 2026-06-18 at 06:00 UTC. In its closure update, Kamu SM stated that no certificates were revoked or issued during the incident window and that all action items were completed, including peer review for manual CRL path changes and Nagios CRL integrity monitoring. CCADB then issued a final call for comments on 2026-07-27 and said the incident report would be closed on approximately 2026-08-03. The bug is now RESOLVED with resolution FIXED.

Model: gpt-5.4-mini Generated: 2026-06-19 19:38 UTC Revised: 2026-08-09 06:01 UTC Confidence: 0.97 8 comments
Chronology
  1. A key rollover for the Mobile Qualified Electronic Certificate subordinate CA caused an incorrect CRL to be served at the production SSL CRL distribution point.
  2. Kamu SM restored the correct CRL at the production distribution point.
  3. Kamu SM completed the Nagios CRL integrity monitoring action item and stated that all action items were complete.
  4. The incident report was scheduled to be closed after the final call for comments.
Thread Activity
  1. Tubitak representative — Posted a preliminary incident report describing the CRL copy service configuration error and noting that the source of disclosure was a third-party report.
  2. Tubitak representative — Posted the full incident report with the timeline, impact, and remediation details, and attached SSL_CRL.zip.
  3. Tubitak representative — Requested a next update of 2026-07-20 while working on an action item.
  4. Tubitak representative — Reported no changes and again requested a next update of 2026-07-20.
  5. Tubitak representative — Reported no changes and said the action item was expected to be finalized and closed by 2026-07-20.
  6. Tubitak representative — Stated that the Nagios CRL integrity monitoring action item was completed, that all action items were complete, and requested closure of the incident report.
  7. CCADB representative — Issued a final call for comments or questions and said the incident report would be closed on approximately 2026-08-03.
Participants
Tubitak representative CCADB representative
Similar Local Cases
#2052399 RESOLVED Incident Self Reported Incident Repository Issue Remediation Tracking Opened 2026-07-03 · Closed 2026-08-08 · 82% similar
Certainly: Expired certificates on "Valid" and "Revoked" test websites
#2048444 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-06-18 · Closed 2026-08-04 · 82% similar
IdenTrust: End Entity TLS certificate mis-issuance against CP/CPS (IdenTrust certificate policy OIDs)
#2058503 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-07-28 · Closed 2026-09-02 · 80% similar
GlobalSign: SubCA created with incorrect CPS Policy OID
#2061909 RESOLVED Ca Certificate Compliance Self Reported Incident Incident Validation Issue Opened 2026-08-08 · Closed 2026-09-11 · 80% similar
Certainly: Test Website Certificate Renewal Failure Following Production Deployment Drift
#2033000 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Policy Document Issue Opened 2026-04-17 · Closed 2026-07-09 · 80% similar
SwissSign: Certificate Profile error for S/MIME MV
#2025595 RESOLVED Self Reported Incident Incident Opened 2026-03-23 · Closed 2026-05-18 · 80% similar
IdenTrust: Delay in updating a Bug 2014609 - Next update
#2052085 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Audit Finding Opened 2026-07-02 · Closed 2026-09-05 · 79% similar
Certainly: Missing audit log entries for certificates issued during capacity testing
#2011314 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Externally Reported Incident Opened 2026-01-19 · Closed 2026-06-23 · 79% similar
Netlock: unspecifed revocation code (0) in CRL

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action