Closed Bug 2054849 Opened 1 month ago Closed 1 month ago

Atos: Incorrect CRL URL in CCADB

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: theo.fischer, Assigned: theo.fischer)

Details

(Whiteboard: [ca-compliance] [disclosure-failure])

Preliminary Incident Report

Summary

  • Incident description:
    Because of an incident Report, we have identified that several CRL URLs in CCADB were disclosed with "https" and therefore don't exactly match as they appear in the issued certificates. The entries have been corrected with the correct URLs.
  • Relevant policies:
    CCADB Policy section 6.2: For any unexpired and unrevoked CA certificate disclosed to the CCADB, CA Owners MUST disclose, in a JSON array, the complete set of distinct HTTP URLs appearing in the crlDistributionPoints extension of the unexpired certificates issued by that CA. The disclosed URLs MUST match exactly as they appear in the issued certificates.
  • Source of incident disclosure:
    Third Party Reported
Assignee: nobody → theo.fischer
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true
Whiteboard: [ca-compliance] [disclosure-failure]

Full Incident Report

Summary

  • CA Owner CCADB unique ID: A000004
  • Incident description: We received a notice of non-compliance that CRL URLs disclosed in CCADB were recorded using the HTTPS scheme, while the corresponding CRL Distribution Point URLs embedded in issued certificates use the HTTP scheme. Although the referenced CRL resources were identical and operational, the CCADB disclosures did not exactly match the certificate contents, resulting in non-conformance with CCADB Policy Section 6.2 disclosure accuracy requirements
  • Timeline summary:
    • Non-compliance start date: 2025-07-15
    • Non-compliance identified date: 2026-07-13
    • Non-compliance end date: 2026-07-13
  • Relevant policies: CCADB Policy Version 2.0 (Effective: July 15, 2025), 6.2 Certificate Revocation List Disclosures
  • Source of incident disclosure: Third party reported

Impact

  • Total number of certificates: N/A
  • Total number of "remaining valid" certificates: N/A
  • Affected certificate types: Intermediate CA Certificate entries in CCADB
  • Incident heuristic: N/A
  • Was issuance stopped in response to this incident, and why or why not?: Issuance was not stopped because the incident only involved inaccurate disclosure of CRL URLs in CCADB. The certificates themselves were unaffected, contained the correct CRL Distribution Point URLs, and no certificate mis-issuance or security impact was identified.
  • Analysis: N/A
  • Additional considerations: N/A

Timeline

All time info in UTC.

2025-07-15 - CCADB Policy 2.0 released
2026-07-13 00:21 - Notice of non-compliance received
2026-07-13 09:31 - Investigation initiated
2026-07-13 12:34 - Investigation completed - 13 Intermediate CA entries with a mismatch detected
2026-07-13 12:55 - Response provided to the reporter
2026-07-13 13:34 - CCADB records updated and correction completed
2026-07-13 14:54 - Follow-up response provided to the reporter
2026-07-14 07:59 - Preliminary incident report published in Bugzilla
2026-07-20 09:10 - Full incident report published on Bugzilla

Related Incidents

Bug Date Description
2007216 2025-12-19 CRL Disclosure in CCADB Mismatch with Issued Certificates
2055047 2026-07-14 Incomplete disclosure of CRL URLs in CCADB
2049012 2026-06-19 Inaccuracy in CRL URL in CCADB
2055120 2026-07-14 Incomplete disclosure of CRL URLs in CCADB
2007072 2025-12-19 CRL disclosure address incorrectly using HTTPS scheme in CCADB
2007098 2025-12-19 Misalignment of CRL URL in CCADB with issued certificates

Root Cause Analysis

Contributing Factor #1: Insufficient Verification Criteria

  • Description: Existing reviews verified that the disclosed CRL URLs were reachable and operational. An independent review was not conducted to confirm that the CRL URLs disclosed in CCADB exactly matched the corresponding CRL Distribution Point URLs contained in issued certificates. As a result, differences in the URL scheme (HTTP versus HTTPS) were not identified.
  • Timeline: 2025-2026
  • Detection: Identified following notice of non-compliance received from third party on 2026-07-13
  • Interaction with other factors: N/A
  • Root Cause Analysis methodology used: 5-Why method

Lessons Learned

  • What went well: The discrepancy was confirmed through an internal compliance review and corrected promptly.
  • What didn’t go well: The CCADB review process relied on a single-person review and did not include verification that disclosed values exactly matched certificate contents.
  • Where we got lucky: The discrepancy was limited to a disclosure issue. Certificate contents, revocation services, and PKI operations were not affected.
  • Additional: N/A

Action Items

Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status
Correct CRL URLs in CCADB Mitigate Root Cause # 1 CRL URLs disclosed in CCADB match CRL URLs in certificate 2026-07-13 Complete
Implement a mandatory four-eyes review process for all CCADB disclosures, changes and reviews. Prevent Root Cause # 1 The action will be considered effective when the four-eyes principle is documented in the relevant checklists and process descriptions. 2026-07-30 ongoing

Appendix

Affected CA Old Entry New Corrected Entry
Atos TrustedRoot Client-CA for Primetals G2 2022 ["https://pki-crl.atos.net/crl/Atos_TrustedRoot_Client_CA_for_Primetals_G2_2022.crl"] ["http://pki-crl.atos.net/crl/Atos_TrustedRoot_Client_CA_for_Primetals_G2_2022.crl"]
Atos TrustedRoot Client-CA for Elopak G2 2022 ["https://pki-crl.atos.net/crl/Atos_TrustedRoot_Client_CA_for_Elopak_G2_2022.crl"] ["http://pki-crl.atos.net/crl/Atos_TrustedRoot_Client_CA_for_Elopak_G2_2022.crl"]
Eviden TrustedRoot Client-CA G2 2023 ["https://pki-crl.atos.net/crl/Eviden_TrustedRoot_Client_CA_G2_2023.crl"] ["http://pki-crl.atos.net/crl/Eviden_TrustedRoot_Client_CA_G2_2023.crl"]
Eviden TrustedRoot Client CA for Primetals 2023 ["https://pki-crl.atos.net/crl/Eviden_TrustedRoot_Client_CA_for_Primetals_2023.crl"] ["http://pki-crl.atos.net/crl/Eviden_TrustedRoot_Client_CA_for_Primetals_2023.crl"]
Eviden TrustedRoot Client CA for Paragon G2 2023 ["https://pki-crl.atos.net/crl/Eviden_TrustedRoot_Client_CA_for_Paragon_G2_2023.crl"] ["http://pki-crl.atos.net/crl/Eviden_TrustedRoot_Client_CA_for_Paragon_G2_2023.crl"]
Eviden TrustedRoot Client CA for Atos 2023 ["https://pki-crl.atos.net/crl/Eviden_TrustedRoot_Client_CA_for_Atos_2023.crl"] ["http://pki-crl.atos.net/crl/Eviden_TrustedRoot_Client_CA_for_Atos_2023.crl"]
Eviden TrustedRoot Client CA for NordLB 2023 ["https://pki-crl.atos.net/crl/Eviden_TrustedRoot_Client_CA_for_NordLB_2023.crl"] ["http://pki-crl.atos.net/crl/Eviden_TrustedRoot_Client_CA_for_NordLB_2023.crl"]
Eviden TrustedRoot Client CA for SPIE 2023 ["https://pki-crl.atos.net/crl/Eviden_TrustedRoot_Client_CA_for_SPIE_2023.crl"] ["http://pki-crl.atos.net/crl/Eviden_TrustedRoot_Client_CA_for_SPIE_2023.crl"]
Eviden TrustedRoot Client CA for Elopak 2023 ["https://pki-crl.atos.net/crl/Eviden_TrustedRoot_Client_CA_for_Elopak_2023.crl"] ["http://pki-crl.atos.net/crl/Eviden_TrustedRoot_Client_CA_for_Elopak_2023.crl"]
Eviden TrustedRoot Mailgateway CA G2 2023 ["https://pki-crl.atos.net/crl/Eviden_TrustedRoot_Mailgateway_CA_G2_2023.crl"] ["http://pki-crl.atos.net/crl/Eviden_TrustedRoot_Mailgateway_CA_G2_2023.crl"]
Eviden TrustedRoot Client CA for Wintershall Dea G2 2023 ["https://pki-crl.atos.net/crl/Eviden_TrustedRoot_Client_CA_for_Wintershall_Dea_G2_2023.crl"] ["http://pki-crl.atos.net/crl/Eviden_TrustedRoot_Client_CA_for_Wintershall_Dea_G2_2023.crl"]
Atos TrustedRoot Server CA ECC 2022 ["https://pki-crl.atos.net/crl/Atos_TrustedRoot_Server_CA_ECC_2022.crl"] ["http://pki-crl.atos.net/crl/Atos_TrustedRoot_Server_CA_ECC_2022.crl"]
Atos TrustedRoot Server CA RSA 2022 ["https://pki-crl.atos.net/crl/Atos_TrustedRoot_Server_CA_RSA_2022.crl"] ["http://pki-crl.atos.net/crl/Atos_TrustedRoot_Server_CA_RSA_2022.crl"]

Work for all action items completed

Action Items

Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status
Correct CRL URLs in CCADB Mitigate Root Cause # 1 CRL URLs disclosed in CCADB match CRL URLs in certificate 2026-07-13 Complete
Implement a mandatory four-eyes review process for all CCADB disclosures, changes and reviews. Prevent Root Cause # 1 The action will be considered effective when the four-eyes principle is documented in the relevant checklists and process descriptions. 2026-07-30 Complete

Report Closure Summary

  • Incident description: On 2026-07-13, Atos received an incident report regarding discrepancies between CRL URLs disclosed in CCADB and the corresponding CRL Distribution Point URLs contained in issued certificates. Several CCADB entries referenced the CRL locations using "https" URLs, while the certificates contained "http" URLs.
  • Incident Root Cause(s): The discrepancy was caused by insufficient verification during the update of CCADB records. While the CRL locations were correctly disclosed from an operational perspective, an independent verification step was not performed to ensure that the URLs entered in CCADB exactly matched the CRL Distribution Point URLs embedded in the corresponding certificates. As a result, protocol differences ("https" vs. "http") remained undetected.
  • Remediation description: All affected CCADB entries were corrected to reflect the exact CRL URLs contained in the corresponding certificates. In addition, the CCADB change management process was updated to require a mandatory four-eyes review of all certificate-related disclosures before publication or modification. The process was further extended to require a four-eyes review of all CCADB entries affected by policy changes or other modifications to publicly disclosed CA information.
  • Commitment summary: Atos is committed to ensuring the accuracy and completeness of all information disclosed in CCADB. Future CCADB updates, including updates resulting from policy changes, will be subject to a mandatory four-eyes review and verification against the corresponding source data prior to publication. This control is intended to prevent discrepancies between CCADB disclosures and the actual certificate or policy content and to ensure ongoing compliance with applicable root store requirements.

All Action Items disclosed in this report have been completed as described, and we request its closure.

This is a final call for comments or questions on this Incident Report.

Otherwise, it will be closed on approximately 2026-07-30.

Whiteboard: [ca-compliance] [disclosure-failure] → [close on 2026-07-30] [ca-compliance] [disclosure-failure]
Status: ASSIGNED → RESOLVED
Closed: 1 month ago
Resolution: --- → FIXED
Whiteboard: [close on 2026-07-30] [ca-compliance] [disclosure-failure] → [ca-compliance] [disclosure-failure]
You need to log in before you can comment on or make changes to this bug.