Closed Bug 2007066 Opened 8 months ago Closed 7 months ago

Disig: Missing CA Disig R2I2 Certification Service Full CRL URLs in CCADB

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: peter.miskovic, Assigned: peter.miskovic)

Details

(Whiteboard: [ca-compliance] [disclosure-failure])

Attachments

(1 file)

Preliminary Incident Report

Summary

  • Incident description: CRL Distribution Point Missing in CCADB for CA Disig R2I2 Certification Service
  • Relevant policies: CCADB Policy 6.2
  • Source of incident disclosure: Certificate Problem Reporting

Disig has resolved the missing CRL distribution point in CCADB on CA Disig R2I2 Certification Service. A full investigation and report are in progress.

Assignee: nobody → peter.miskovic
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true
Whiteboard: [ca-compliance] [disclosure-failure]

Full Incident Report

Summary

  • CA Owner CCADB unique ID: A000008
  • Incident description: Disig: Missing CA Disig R2I2 Certification Service Full CRL URLs in CCADB
  • Timeline summary:
    • Non-compliance start date: 2025-07-15
    • Non-compliance identified date: 2025-12-18
    • Non-compliance end date: 2025-12-19
  • Relevant policies: CCADB policy 6.2 requires the full CRL URL to be updated within 7 days of the first certificate issued by the CA certificate*
  • Source of incident disclosure: Certificate Problem Reporting

Impact

  • Total number of certificates: Single(1) Subordinate CA Certificate CCADB entries
  • Total number of "remaining valid" certificates: 0
  • Affected certificate types: Subordinate CA Certificate CCADB entries
  • Incident heuristic: 3
  • Was issuance stopped in response to this incident, and why or why not?: No, there was no misissuance and the appropriate CCADB entries were updated promptly to correct the issue.

Timeline

  • 2025-07-15 - CCADB Policy Version 2.0 started be effective with the 6.2 Certificate Revocation List Disclosures section

  • 2025-12-18 21:03 - Disig has received a report of an issue with the information about the subordinate certificate of CA Disig R2I2 Certification Service published in CCADB, where the Pertaining to Certificates Issued by this CA section lists the URL for the Full CRL issued by this CA, which is not found in the issued valid TLS certificates for end clients.

  • 2025-12-18 22:10 - Disig confirms the missing full CRL URL from CCADB and identifies one (1) intermediate certificate is impacted

  • 2025-12-19 10:30 - Disig created a bug No. [2007066] at Bugzilla

  • 2025-12-19 10:35 - CCADB entries for CA Disig R2I2 Certification Service full CRL URLs is updated (out of compliance end)

Root Cause Analysis

Contributing Factor 1 title Existence of multiple DNS record

  • Description: CA Disig has multiple DNS records available for storing data on issued CRLs, where one of them, marked as cdp.disig.sk, is intended for access only to issued CRLs, and the other, marked as cdn.disig.sk, is essentially an alias for more global use, which allows access to data other than CRLs in addition to access to CRL data. As for CRLs, both DNS names point to the same CA Disig IS publication servers and return the same current CRL file.
  • Timeline: Both distributing point exist from CA Disig R2I2 Certification Service creation e.g 2014-10-02
  • Detection: Full investigation of root cause
  • Interaction with other factors: Contributing factor #2 & #3

Contributing Factor 2 title Existence of CCADB record with URL: http://cdp.disig.sk/subcar2i2/crl/subcar2i2.crl

  • Description: In CCADB, there was a CRL distribution point entry for CA Disig R2I2 Certification Service with a URL (http://cdn.disig.sk/subcar2i2/crl/subcar2i2.crl) that pointed to the same CRL file.
  • Timeline: 2024-01-17
  • Detection: Full investigation of root cause
  • Interaction with other factors: Contributing factor #1 & #3

Contributing Factor 3 title Change of CCADB Policy

  • Description: Change of policy for CCADB from version 1.3.1 to version 2.0 where in first one there were no requirements regarding CRL publication points and their listing in CCADB.
  • Timeline: 2025-07-15
  • Detection: Full investigation of root cause
  • Interaction with other factors: Contributing factors #1 & #2

Contributing Factor 4 title Insufficient attention paid to CCADB policy changes

  • Description: The person responsible in our company for updating data in CCADBB did not pay sufficient attention to the fact that the data provided by CA Disig R2I2 Certification Service about the distribution point corresponds to the updated requirements of version 2.0 of the CCADB policy with what is stated in the TLS certificate profile issued by this subordinate CA, which was probably also contributed to by the great similarity of the URL addresses of the distribution points used - see Contributing Factor 2
  • Timeline: 2025-07-15
  • Detection: Full investigation of root cause
  • Interaction with other factors:

Lessons Learned

  • What went well: Disig had been correctly generating and hosting CRLs for the CA Disig R2I2 certification service on two different distribution points that referenced the same CRL file for a long time. The problem was that the URL of the first distribution point, which was in the issued TLS certificate profile, was not registered in CCADB, while the URL of the second distribution point was registered there.
  • What didn’t go well: Human error led to an oversight of the requirement, after updating the CCADB policy, to update the full CRL URL to the one actually listed in the issued TLS certificates.
  • Where we got lucky: There was no TLS certificate misissuance, but only an incorrect distribution point entry in CCADB.
  • Additional: Disig will ensure that CCADB expectations and policies are properly implemented

Action Items

Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status
Comprehensive Audit of all CCADB entries and TLS profiles. Corrective Root Cause # 3 100% verification of all distribution points against current policies. 2025-12-19 Complete
Implementation of Dual-Control (Four-Eyes) validation for CCADB updates. Preventative Root Cause # 1 Updated internal procedure manual and documented approval logs. 2025-12-19 (and ongoing) Planned
Development of a Compliance Mapping Checklist for policy updates. Preventative Root Cause # 3 Formalized checklist used for every future issuance/update. 2026-01-09 In Progress

Appendix

See attached CSV for impacted intermediate.

This report has gone stale. As a reminder, CA Owners may request the “Next update” Whiteboard field be set by a Root Store Operator to align with a specific date related to an open Action Item.

Flags: needinfo?(peter.miskovic)

Action Item #3 was completed on 2026-01-05.

Flags: needinfo?(peter.miskovic)

Report Closure Summary

  • Incident description: The incident involved incorrect use of Distribution Point (DP) URLs in certificate profiles that did not comply with the updated technical requirements specified in the CCADB policy version 2.0. This discrepancy occurred specifically within the subordinate CA Disig R2I2 certification service, where a different URI was specified for issued TLS certificates than the one specified in the CCADB for the given subordinate CA, even though both of these distribution points resulted in an identical Certificate Revocation List (CRL).

  • Incident Root Cause(s): The root cause was identified as a combination of human error and procedural deficiency. The responsible personnel failed to identify specific changes in the updated CCADB policy requirements due to the high visual similarity between the old and new Distribution Point URLs. This led to an overlooked misalignment between the CCADB data entry and the actual TLS certificate profile.

  • Remediation description: Immediate remediation involved a comprehensive cross-check audit of all active CCADB entries against current policy requirements. We have updated the internal verification procedures to include a "four-eyes" validation step for all CCADB modifications. Additionally, a specialized compliance checklist was introduced to ensure that any policy version transitions (e.g., v1.x to v2.0) are systematically mapped against our certificate profiles.

  • Commitment summary: We remain committed to maintaining the integrity of the CCADB data.

All Action Items disclosed in this report have been completed as described, and we request its closure.

This is a final call for comments or questions on this Incident Report.

Otherwise, it will be closed on approximately 2026-01-20.

Flags: needinfo?(incident-reporting)
Whiteboard: [ca-compliance] [disclosure-failure] → [close on 2026-01-20] [ca-compliance] [disclosure-failure]

Action Items update

Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status
Containment: temporarily remove https://gouda2027h1.log.ct.ipng.ch/ from the active CT submission list to prevent recurrence until the finalization fix + CT/SCT validation are deployed and verified. Corrective RC #4 (1) Config change approved & documented (change ticket + diff). Issuance continues successfully with remaining CT logs; required SCT quantity/diversity for affected lifetimes is met. (3) No new pkimetal/crt.sh findings of this failure mode during containment window. 2025-12-19
Identify all impacted certificates (time window while gouda2027h1 was enabled + detection rules for SCT/CT signature mismatch). Corrective RC #1, RC#4 Complete list and count of impacted certs 2025-12-19 Complete
Revocation of all affected certificates and reissuance of new ones with remaining CT log records Corrective RC #1 All impacted certs revoked. 2025-12-19 Complete
Integrate the "ctlint" linter into the pre-issuance pipeline. This check must occur on the final certificate candidate and block issuance if the SCT structure is invalid. Preventive RC #1, #2, #3 and #4 Issuance blocked on ctlint failures (100% coverage); 2026-02-06 Ongoing
Integrate the "ctlint" linter into the pre-issuance pipeline. This check must occur on the final certificate candidate and block issuance if the SCT structure is invalid. Preventive RC #1, #2, #3 and #4 0 SCT-structure findings in CT (pkimetal/crt.sh) for new issuance. 2026-02-06 Ongoing
Strengthen change control for issuance-critical code paths (4-eyes review + CT-specific checklist: byte preservation Preventive RC #1 00% issuance-critical PRs: 2 approvals + CT checklist 2025-12-19 (and ongoing) Planned
Strengthen change control for issuance-critical code paths (4-eyes review + CT-specific checklist: byte preservation Preventive RC #1 0 CT/SCT regressions from issuance changes (tracked; verifiable via CT/pkimetal)</p> 2025-12-19 (and ongoing) Planned

Correction to my previous comment: please ignore the information above.

It is for bug https://bugzilla.mozilla.org/buglist.cgi?quicksearch=Disig&list_id=17816622.

Status: ASSIGNED → RESOLVED
Closed: 7 months ago
Flags: needinfo?(incident-reporting)
Resolution: --- → FIXED
Whiteboard: [close on 2026-01-20] [ca-compliance] [disclosure-failure] → [ca-compliance] [disclosure-failure]
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: