D-TRUST: Incomplete disclosure of CRL URLs in CCADB records
D-TRUST’s case concerns incomplete disclosure of CRL URLs in CCADB records for its Root and Subordinate CA certificates. The issue was first reported externally on 2026-07-13 through a Certificate Problem Report, which said that HTTP URLs in the certificates’ crlDistributionPoints extensions were missing from the corresponding CCADB fields. D-TRUST confirmed the disclosure gap, said certificate validity was not affected, and stated that no revocation was required. The revised incident report says the non-compliance began when CCADB Policy Version 2.1 took effect on 2026-03-20 and that D-TRUST’s records and automated reconciliation did not account for every Full CRL URL required by the updated disclosure rule. D-TRUST corrected the subordinate CA entries on 2026-07-24 and later used a CCADB support case to correct the root CA entries as well. Mozilla then said the full incident report still did not meet the expected standard and asked D-TRUST to revise it with a more complete root cause analysis and updated corrective, preventive, and detective actions. On 2026-08-27, D-TRUST posted another revised full incident report and corrected the affected record count to 30.
- CCADB Policy Version 2.1 took effect with updated CRL disclosure requirements.
- A community member filed a Certificate Problem Report about CRL URLs missing from CCADB disclosure records.
- D-TRUST corrected the affected subordinate CA Full CRL URL entries in CCADB.
- D-TRUST opened a CCADB support case so the root CA entries could also be corrected.
- D-TRUST posted a revised full incident report with updated counts and analysis.
- Bdr representative — Submitted a preliminary incident report confirming the missing CCADB CRL URLs, stating no revocation was required, and saying a full incident report would follow.
- D-Trust — Posted the full incident report, described the affected CCADB entries, root cause, timeline, and action items, and noted the correction of the CCADB data.
- D-Trust — Reported that a support case was opened with CCADB so the root CA entries could also be corrected.
- D-Trust — Posted a revised incident report, corrected dates and action-item status, said the root CA entries were corrected through the CCADB support case, and requested the Next update field be set to 2026-10-01.
- Bdr representative — Said the full incident report still did not meet the expected standard and asked D-TRUST to revise it with a more complete root cause analysis and updated corrective, preventive, and detective actions.
- D-Trust — Said the revised final incident report would be posted shortly.
- D-Trust — Posted a revised full incident report stating the corrected affected-record count was 30 and explaining the updated CCADB Policy 2.1 disclosure requirement.