Atos: Incorrect CRL URL in CCADB
Categories
(CA Program :: CA Certificate Compliance, task)
Tracking
(Not tracked)
People
(Reporter: theo.fischer, Assigned: theo.fischer)
Details
(Whiteboard: [ca-compliance] [disclosure-failure])
Preliminary Incident Report
Summary
- Incident description:
Because of an incident Report, we have identified that several CRL URLs in CCADB were disclosed with "https" and therefore don't exactly match as they appear in the issued certificates. The entries have been corrected with the correct URLs. - Relevant policies:
CCADB Policy section 6.2: For any unexpired and unrevoked CA certificate disclosed to the CCADB, CA Owners MUST disclose, in a JSON array, the complete set of distinct HTTP URLs appearing in the crlDistributionPoints extension of the unexpired certificates issued by that CA. The disclosed URLs MUST match exactly as they appear in the issued certificates. - Source of incident disclosure:
Third Party Reported
Updated•1 month ago
|
| Assignee | ||
Comment 1•1 month ago
|
||
Full Incident Report
Summary
- CA Owner CCADB unique ID: A000004
- Incident description: We received a notice of non-compliance that CRL URLs disclosed in CCADB were recorded using the HTTPS scheme, while the corresponding CRL Distribution Point URLs embedded in issued certificates use the HTTP scheme. Although the referenced CRL resources were identical and operational, the CCADB disclosures did not exactly match the certificate contents, resulting in non-conformance with CCADB Policy Section 6.2 disclosure accuracy requirements
- Timeline summary:
- Non-compliance start date: 2025-07-15
- Non-compliance identified date: 2026-07-13
- Non-compliance end date: 2026-07-13
- Relevant policies: CCADB Policy Version 2.0 (Effective: July 15, 2025), 6.2 Certificate Revocation List Disclosures
- Source of incident disclosure: Third party reported
Impact
- Total number of certificates: N/A
- Total number of "remaining valid" certificates: N/A
- Affected certificate types: Intermediate CA Certificate entries in CCADB
- Incident heuristic: N/A
- Was issuance stopped in response to this incident, and why or why not?: Issuance was not stopped because the incident only involved inaccurate disclosure of CRL URLs in CCADB. The certificates themselves were unaffected, contained the correct CRL Distribution Point URLs, and no certificate mis-issuance or security impact was identified.
- Analysis: N/A
- Additional considerations: N/A
Timeline
All time info in UTC.
2025-07-15 - CCADB Policy 2.0 released
2026-07-13 00:21 - Notice of non-compliance received
2026-07-13 09:31 - Investigation initiated
2026-07-13 12:34 - Investigation completed - 13 Intermediate CA entries with a mismatch detected
2026-07-13 12:55 - Response provided to the reporter
2026-07-13 13:34 - CCADB records updated and correction completed
2026-07-13 14:54 - Follow-up response provided to the reporter
2026-07-14 07:59 - Preliminary incident report published in Bugzilla
2026-07-20 09:10 - Full incident report published on Bugzilla
Related Incidents
| Bug | Date | Description |
|---|---|---|
| 2007216 | 2025-12-19 | CRL Disclosure in CCADB Mismatch with Issued Certificates |
| 2055047 | 2026-07-14 | Incomplete disclosure of CRL URLs in CCADB |
| 2049012 | 2026-06-19 | Inaccuracy in CRL URL in CCADB |
| 2055120 | 2026-07-14 | Incomplete disclosure of CRL URLs in CCADB |
| 2007072 | 2025-12-19 | CRL disclosure address incorrectly using HTTPS scheme in CCADB |
| 2007098 | 2025-12-19 | Misalignment of CRL URL in CCADB with issued certificates |
Root Cause Analysis
Contributing Factor #1: Insufficient Verification Criteria
- Description: Existing reviews verified that the disclosed CRL URLs were reachable and operational. An independent review was not conducted to confirm that the CRL URLs disclosed in CCADB exactly matched the corresponding CRL Distribution Point URLs contained in issued certificates. As a result, differences in the URL scheme (HTTP versus HTTPS) were not identified.
- Timeline: 2025-2026
- Detection: Identified following notice of non-compliance received from third party on 2026-07-13
- Interaction with other factors: N/A
- Root Cause Analysis methodology used: 5-Why method
Lessons Learned
- What went well: The discrepancy was confirmed through an internal compliance review and corrected promptly.
- What didn’t go well: The CCADB review process relied on a single-person review and did not include verification that disclosed values exactly matched certificate contents.
- Where we got lucky: The discrepancy was limited to a disclosure issue. Certificate contents, revocation services, and PKI operations were not affected.
- Additional: N/A
Action Items
| Action Item | Kind | Corresponding Root Cause(s) | Evaluation Criteria | Due Date | Status |
|---|---|---|---|---|---|
| Correct CRL URLs in CCADB | Mitigate | Root Cause # 1 | CRL URLs disclosed in CCADB match CRL URLs in certificate | 2026-07-13 | Complete |
| Implement a mandatory four-eyes review process for all CCADB disclosures, changes and reviews. | Prevent | Root Cause # 1 | The action will be considered effective when the four-eyes principle is documented in the relevant checklists and process descriptions. | 2026-07-30 | ongoing |
Appendix
| Assignee | ||
Comment 2•1 month ago
|
||
Work for all action items completed
Action Items
| Action Item | Kind | Corresponding Root Cause(s) | Evaluation Criteria | Due Date | Status |
|---|---|---|---|---|---|
| Correct CRL URLs in CCADB | Mitigate | Root Cause # 1 | CRL URLs disclosed in CCADB match CRL URLs in certificate | 2026-07-13 | Complete |
| Implement a mandatory four-eyes review process for all CCADB disclosures, changes and reviews. | Prevent | Root Cause # 1 | The action will be considered effective when the four-eyes principle is documented in the relevant checklists and process descriptions. | 2026-07-30 | Complete |
| Assignee | ||
Comment 3•1 month ago
|
||
Report Closure Summary
- Incident description: On 2026-07-13, Atos received an incident report regarding discrepancies between CRL URLs disclosed in CCADB and the corresponding CRL Distribution Point URLs contained in issued certificates. Several CCADB entries referenced the CRL locations using "https" URLs, while the certificates contained "http" URLs.
- Incident Root Cause(s): The discrepancy was caused by insufficient verification during the update of CCADB records. While the CRL locations were correctly disclosed from an operational perspective, an independent verification step was not performed to ensure that the URLs entered in CCADB exactly matched the CRL Distribution Point URLs embedded in the corresponding certificates. As a result, protocol differences ("https" vs. "http") remained undetected.
- Remediation description: All affected CCADB entries were corrected to reflect the exact CRL URLs contained in the corresponding certificates. In addition, the CCADB change management process was updated to require a mandatory four-eyes review of all certificate-related disclosures before publication or modification. The process was further extended to require a four-eyes review of all CCADB entries affected by policy changes or other modifications to publicly disclosed CA information.
- Commitment summary: Atos is committed to ensuring the accuracy and completeness of all information disclosed in CCADB. Future CCADB updates, including updates resulting from policy changes, will be subject to a mandatory four-eyes review and verification against the corresponding source data prior to publication. This control is intended to prevent discrepancies between CCADB disclosures and the actual certificate or policy content and to ensure ongoing compliance with applicable root store requirements.
All Action Items disclosed in this report have been completed as described, and we request its closure.
Comment 4•1 month ago
|
||
This is a final call for comments or questions on this Incident Report.
Otherwise, it will be closed on approximately 2026-07-30.
Updated•1 month ago
|
Description
•