← Amazon Trust Services cases
Bugzilla #1914893 Technical Compliance

Amazon Trust Services: CRL not DER-encoded

RESOLVED FIXED Amazon Trust Services
AI Summary

Amazon Trust Services faced an issue where a Certificate Revocation List (CRL) was served in PEM format instead of the required DER format, violating RFC5280. This was due to a recent change to an automated deployment process that did not include checks for CRL format. The issue was identified during a regular review, and corrective actions were taken to ensure compliance. The CRL was updated to the correct format shortly after the issue was discovered, and Amazon Trust Services has since requested the case be closed as resolved.

Model: gpt-4o-mini Generated: 2026-06-13 15:29 UTC Confidence: 1.00
Chronology
  1. Deployed new CRL to the specified URI.
  2. Regular review of CRLWatch identified a parsing error.
  3. Incident identified during the next regular review.
  4. Updated CRL in correct format completed deployment.
  5. Requested closure of the issue as resolved.
Participants
Andrew Ayer Trevoli (Amazon Trust Services) bwilson@mozilla.com
External References
Similar Local Cases
#1746945 RESOLVED Technical Compliance Opened 2021-12-20 · Closed 2023-02-22 · 60% similar
Amazon Trust Services: Missing CAA Check For Test Website Certificates
#1521623 RESOLVED Technical Compliance Opened 2019-01-21 · Closed 2024-05-09 · 57% similar
Amazon Trust Services: Failure to comply with RFC 5280
#1772644 RESOLVED Technical Compliance Opened 2022-06-04 · Closed 2023-02-22 · 47% similar
Apple: CRL issuance frequency deviates from CPS in some cases
#1428891 RESOLVED Technical Compliance Opened 2018-01-08 · Closed 2023-02-22 · 41% similar
Entrust: Non-BR-Compliant OCSP Responder
#1398240 RESOLVED Technical Compliance Opened 2017-09-08 · Closed 2023-02-22 · 39% similar
Firmaprofesional: Non-BR-Compliant OCSP Responders
#1800405 RESOLVED Certificate Problem Report Opened 2022-11-14 · Closed 2023-02-22 · 39% similar
Amazon Trust Services / DigiCert: 404 error when fetching CRL
#1444455 RESOLVED Technical Compliance Opened 2018-03-09 · Closed 2023-02-22 · 38% similar
DocuSign/Keynectis: Non-Compliant Technically Constrained Intermediates
#1398261 RESOLVED Technical Compliance Opened 2017-09-08 · Closed 2023-02-22 · 38% similar
Visa: Non-BR-Compliant OCSP Responders

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action