Disig: Missing CA Disig R2I2 Certification Service Full CRL URLs in CCADB
Categories
(CA Program :: CA Certificate Compliance, task)
Tracking
(Not tracked)
People
(Reporter: peter.miskovic, Assigned: peter.miskovic)
Details
(Whiteboard: [ca-compliance] [disclosure-failure])
Attachments
(1 file)
|
3.29 KB,
text/csv
|
Details |
Preliminary Incident Report
Summary
- Incident description: CRL Distribution Point Missing in CCADB for CA Disig R2I2 Certification Service
- Relevant policies: CCADB Policy 6.2
- Source of incident disclosure: Certificate Problem Reporting
Disig has resolved the missing CRL distribution point in CCADB on CA Disig R2I2 Certification Service. A full investigation and report are in progress.
| Assignee | ||
Comment 1•8 months ago
|
||
Updated•8 months ago
|
| Assignee | ||
Comment 2•8 months ago
|
||
Full Incident Report
Summary
- CA Owner CCADB unique ID: A000008
- Incident description: Disig: Missing CA Disig R2I2 Certification Service Full CRL URLs in CCADB
- Timeline summary:
- Non-compliance start date: 2025-07-15
- Non-compliance identified date: 2025-12-18
- Non-compliance end date: 2025-12-19
- Relevant policies: CCADB policy 6.2 requires the full CRL URL to be updated within 7 days of the first certificate issued by the CA certificate*
- Source of incident disclosure: Certificate Problem Reporting
Impact
- Total number of certificates: Single(1) Subordinate CA Certificate CCADB entries
- Total number of "remaining valid" certificates: 0
- Affected certificate types: Subordinate CA Certificate CCADB entries
- Incident heuristic: 3
- Was issuance stopped in response to this incident, and why or why not?: No, there was no misissuance and the appropriate CCADB entries were updated promptly to correct the issue.
Timeline
-
2025-07-15 - CCADB Policy Version 2.0 started be effective with the 6.2 Certificate Revocation List Disclosures section
-
2025-12-18 21:03 - Disig has received a report of an issue with the information about the subordinate certificate of CA Disig R2I2 Certification Service published in CCADB, where the Pertaining to Certificates Issued by this CA section lists the URL for the Full CRL issued by this CA, which is not found in the issued valid TLS certificates for end clients.
-
2025-12-18 22:10 - Disig confirms the missing full CRL URL from CCADB and identifies one (1) intermediate certificate is impacted
-
2025-12-19 10:30 - Disig created a bug No. [2007066] at Bugzilla
-
2025-12-19 10:35 - CCADB entries for CA Disig R2I2 Certification Service full CRL URLs is updated (out of compliance end)
Root Cause Analysis
Contributing Factor 1 title Existence of multiple DNS record
- Description: CA Disig has multiple DNS records available for storing data on issued CRLs, where one of them, marked as cdp.disig.sk, is intended for access only to issued CRLs, and the other, marked as cdn.disig.sk, is essentially an alias for more global use, which allows access to data other than CRLs in addition to access to CRL data. As for CRLs, both DNS names point to the same CA Disig IS publication servers and return the same current CRL file.
- Timeline: Both distributing point exist from CA Disig R2I2 Certification Service creation e.g 2014-10-02
- Detection: Full investigation of root cause
- Interaction with other factors: Contributing factor #2 & #3
Contributing Factor 2 title Existence of CCADB record with URL: http://cdp.disig.sk/subcar2i2/crl/subcar2i2.crl
- Description: In CCADB, there was a CRL distribution point entry for CA Disig R2I2 Certification Service with a URL (http://cdn.disig.sk/subcar2i2/crl/subcar2i2.crl) that pointed to the same CRL file.
- Timeline: 2024-01-17
- Detection: Full investigation of root cause
- Interaction with other factors: Contributing factor #1 & #3
Contributing Factor 3 title Change of CCADB Policy
- Description: Change of policy for CCADB from version 1.3.1 to version 2.0 where in first one there were no requirements regarding CRL publication points and their listing in CCADB.
- Timeline: 2025-07-15
- Detection: Full investigation of root cause
- Interaction with other factors: Contributing factors #1 & #2
Contributing Factor 4 title Insufficient attention paid to CCADB policy changes
- Description: The person responsible in our company for updating data in CCADBB did not pay sufficient attention to the fact that the data provided by CA Disig R2I2 Certification Service about the distribution point corresponds to the updated requirements of version 2.0 of the CCADB policy with what is stated in the TLS certificate profile issued by this subordinate CA, which was probably also contributed to by the great similarity of the URL addresses of the distribution points used - see Contributing Factor 2
- Timeline: 2025-07-15
- Detection: Full investigation of root cause
- Interaction with other factors:
Lessons Learned
- What went well: Disig had been correctly generating and hosting CRLs for the CA Disig R2I2 certification service on two different distribution points that referenced the same CRL file for a long time. The problem was that the URL of the first distribution point, which was in the issued TLS certificate profile, was not registered in CCADB, while the URL of the second distribution point was registered there.
- What didn’t go well: Human error led to an oversight of the requirement, after updating the CCADB policy, to update the full CRL URL to the one actually listed in the issued TLS certificates.
- Where we got lucky: There was no TLS certificate misissuance, but only an incorrect distribution point entry in CCADB.
- Additional: Disig will ensure that CCADB expectations and policies are properly implemented
Action Items
| Action Item | Kind | Corresponding Root Cause(s) | Evaluation Criteria | Due Date | Status |
|---|---|---|---|---|---|
| Comprehensive Audit of all CCADB entries and TLS profiles. | Corrective | Root Cause # 3 | 100% verification of all distribution points against current policies. | 2025-12-19 | Complete |
| Implementation of Dual-Control (Four-Eyes) validation for CCADB updates. | Preventative | Root Cause # 1 | Updated internal procedure manual and documented approval logs. | 2025-12-19 (and ongoing) | Planned |
| Development of a Compliance Mapping Checklist for policy updates. | Preventative | Root Cause # 3 | Formalized checklist used for every future issuance/update. | 2026-01-09 | In Progress |
Appendix
See attached CSV for impacted intermediate.
| Assignee | ||
Comment 3•8 months ago
|
||
Comment 4•7 months ago
|
||
This report has gone stale. As a reminder, CA Owners may request the “Next update” Whiteboard field be set by a Root Store Operator to align with a specific date related to an open Action Item.
| Assignee | ||
Comment 5•7 months ago
|
||
Action Item #3 was completed on 2026-01-05.
| Assignee | ||
Comment 6•7 months ago
|
||
Report Closure Summary
-
Incident description: The incident involved incorrect use of Distribution Point (DP) URLs in certificate profiles that did not comply with the updated technical requirements specified in the CCADB policy version 2.0. This discrepancy occurred specifically within the subordinate CA Disig R2I2 certification service, where a different URI was specified for issued TLS certificates than the one specified in the CCADB for the given subordinate CA, even though both of these distribution points resulted in an identical Certificate Revocation List (CRL).
-
Incident Root Cause(s): The root cause was identified as a combination of human error and procedural deficiency. The responsible personnel failed to identify specific changes in the updated CCADB policy requirements due to the high visual similarity between the old and new Distribution Point URLs. This led to an overlooked misalignment between the CCADB data entry and the actual TLS certificate profile.
-
Remediation description: Immediate remediation involved a comprehensive cross-check audit of all active CCADB entries against current policy requirements. We have updated the internal verification procedures to include a "four-eyes" validation step for all CCADB modifications. Additionally, a specialized compliance checklist was introduced to ensure that any policy version transitions (e.g., v1.x to v2.0) are systematically mapped against our certificate profiles.
-
Commitment summary: We remain committed to maintaining the integrity of the CCADB data.
All Action Items disclosed in this report have been completed as described, and we request its closure.
Comment 7•7 months ago
|
||
This is a final call for comments or questions on this Incident Report.
Otherwise, it will be closed on approximately 2026-01-20.
| Assignee | ||
Comment 8•7 months ago
|
||
Action Items update
| Action Item | Kind | Corresponding Root Cause(s) | Evaluation Criteria | Due Date | Status |
|---|---|---|---|---|---|
| Containment: temporarily remove https://gouda2027h1.log.ct.ipng.ch/ from the active CT submission list to prevent recurrence until the finalization fix + CT/SCT validation are deployed and verified. | Corrective | RC #4 | (1) Config change approved & documented (change ticket + diff). | Issuance continues successfully with remaining CT logs; required SCT quantity/diversity for affected lifetimes is met. (3) No new pkimetal/crt.sh findings of this failure mode during containment window. | 2025-12-19 |
| Identify all impacted certificates (time window while gouda2027h1 was enabled + detection rules for SCT/CT signature mismatch). | Corrective | RC #1, RC#4 | Complete list and count of impacted certs | 2025-12-19 | Complete |
| Revocation of all affected certificates and reissuance of new ones with remaining CT log records | Corrective | RC #1 | All impacted certs revoked. | 2025-12-19 | Complete |
| Integrate the "ctlint" linter into the pre-issuance pipeline. This check must occur on the final certificate candidate and block issuance if the SCT structure is invalid. | Preventive | RC #1, #2, #3 and #4 | Issuance blocked on ctlint failures (100% coverage); | 2026-02-06 | Ongoing |
| Integrate the "ctlint" linter into the pre-issuance pipeline. This check must occur on the final certificate candidate and block issuance if the SCT structure is invalid. | Preventive | RC #1, #2, #3 and #4 | 0 SCT-structure findings in CT (pkimetal/crt.sh) for new issuance. | 2026-02-06 | Ongoing |
| Strengthen change control for issuance-critical code paths (4-eyes review + CT-specific checklist: byte preservation | Preventive | RC #1 | 00% issuance-critical PRs: 2 approvals + CT checklist | 2025-12-19 (and ongoing) | Planned |
| Strengthen change control for issuance-critical code paths (4-eyes review + CT-specific checklist: byte preservation | Preventive | RC #1 | 0 CT/SCT regressions from issuance changes (tracked; verifiable via CT/pkimetal)</p> | 2025-12-19 (and ongoing) | Planned |
| Assignee | ||
Comment 9•7 months ago
|
||
Correction to my previous comment: please ignore the information above.
It is for bug https://bugzilla.mozilla.org/buglist.cgi?quicksearch=Disig&list_id=17816622.
Updated•7 months ago
|
Description
•