Atos CCADB disclosure mismatch for CRL URLs
Atos reported a CCADB compliance issue involving CRL Distribution Point URLs that were disclosed with the HTTPS scheme in CCADB, while the corresponding issued certificates used HTTP URLs. The company said the CRL resources were operational and the certificates themselves were unaffected, but the CCADB entries did not exactly match the certificate contents as required by CCADB Policy section 6.2. Atos corrected the affected CCADB records and later completed a process change requiring a mandatory four-eyes review for CCADB disclosures and related changes. The incident was reported as third-party reported, and Atos requested closure after stating that all action items were complete. The bug is resolved as FIXED.
- CCADB Policy 2.0 took effect, including requirements for exact CRL URL disclosure.
- Atos identified that several CCADB CRL URLs used HTTPS while the issued certificates used HTTP.
- Atos corrected the affected CCADB records.
- The bug was later resolved as FIXED.
- Atos representative — Atos filed a preliminary incident report saying the CCADB CRL URLs did not exactly match the issued certificates and that the entries had been corrected.
- Atos representative — Atos filed a full incident report describing the non-compliance, the timeline, the root cause, and the corrective actions.
- Atos representative — Atos said all action items were complete.
- Atos representative — Atos requested closure and summarized the remediation and process updates.
- CCADB representative — CCADB incident reporting noted this was a final call for comments before closure.