Closed Bug 2055047 Opened 1 month ago Closed 19 days ago

DigiCert: Incomplete disclosure of CRL URLs in CCADB

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: dcbugzillaresponse, Assigned: dcbugzillaresponse)

Details

(Whiteboard: [ca-compliance] [disclosure-failure])

Attachments

(1 file)

Preliminary Incident Report

Summary

  • Incident description: The URLs disclosed in CCADB are not comprehensive for the CRLs of certain DigiCert CAs.
  • Relevant policies: CCADB Policy, Section 6.2 (v2.1, effective 2026-03-20 requires disclosure of "the complete set of distinct HTTP URLs") and (v2.0 effective 2025-07-15 required URLs to "match exactly as they appear in the certificates issued").
  • Source of incident disclosure: Third party reported.
Assignee: nobody → dcbugzillaresponse
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true
Whiteboard: [ca-compliance] [disclosure-failure]

DigiCert is preparing its full incident report and will post it on or before 2026-07-26.

Full Incident Report

Summary

  • CA Owner CCADB unique ID: A000021
  • Incident description: On 2026-07-14, DigiCert received a third-party report alleging undisclosed CRLs in two certificates. An additional 15 certificates were found to have undisclosed CRLs through our internal investigation. Since this issue is related to a previous bug, we conducted deep investigation to determine why some got missed. A number of changes were made to both our disclosures and to our CCADB automation to help ensure our internal systems and CCADB disclosures are always in sync going forward. Additional improvements to the automation of CRLDP were implemented on 2026-07-21. The CRLDPs in the initial report were updated on 2026-07-14, and the remaining on 2026-07-23.
  • Timeline summary:
    • Non-compliance start date: 2025-07-15 (date of first known deviation from CCADB-reported CRLDP in leaf certificates)
    • Non-compliance identified date: 2026-07-14 00:18:11 UTC
    • Non-compliance end date: 2026-07-23 14:20:00 UTC
  • Relevant policies: CCADB Policy, Section 6.2 (Certificate Revocation List Disclosures) (Version 2.0 effective 2025-07-15) and (Version 2.1 effective 2026-03-20). CCADB Policy v2.1 introduced the "JSON Array of all Full CRL URLs" field.
  • Source of incident disclosure: Third Party Reported

Impact

  • Total number of certificates: This incident concerns CRLDP disclosures, not subscriber certificate mis-issuance.
  • Total number of "remaining valid" certificates: N/A
  • Affected certificate types: OV, EV
  • Incident heuristic: A user can compare CCADB filings with the CRLDP presented in leaf certificates.
  • Was issuance stopped in response to this incident, and why or why not?: Issuance was not stopped as this was a CCADB synch error that did not affect the accuracy or availability of revocation information served at the disclosed URLs.
  • Analysis: N/A. This is not a delayed-revocation incident.
  • Additional considerations: This incident overlaps with Bug 2007219.

Timeline

All times are UTC.

2025-07-15 - The original noncompliance date stated in Bug 2007219.
2025-12-19 00:36:00 - Related DigiCert Bug 2007219, was opened. The certificates identified in this incident have the same issue as others identified in that Bug. The CRLDPs were corrected in our origin server for CCADB automation, but were not subsequently pushed to CCADB as they were tagged “quovadis” not the expected “digicert” value. Verification occurred on the origin server, not CCADB’s web interface.
2026-02-17 03:25:00 - Bug 2007219 closed.
2026-03-20 00:00:00 - CCADB Policy Section 6.2 (v2.1) changes to require disclosure of the complete set of distinct HTTP CRL URLs; CCADB introduces the new "JSON Array of all Full CRL URLs" field and revises the "Full CRL Issued By This CA" field.
2026-07-14 00:18:11 - Third-party report received by email reporting that leaf certificates issued from "DigiCert QV EV TLS ICA G1" and "DigiCert QuoVadis TLS ICA QV Root CA 3 G3" include additional full CRLDP beyond those disclosed in the CCADB.
2026-07-14 16:46:00 - Metatag configuration for 6 CAs changed to owner=digicert.
2026-07-21 03:41:00 - Update to dependents systems deployed.
2026-07-23 14:20:00 UTC - Metatag configuration for 11 remaining CAs changed to owner=digicert. Verified no other unexpected metatag values existed in CCADB population.
2027-07-25: 12:48:00 UTC - Resynch of all CRLDP complete.

Related Incidents

Bug Date Description
1990801 2025-09-25 Microsoft PKI Services: improper disclosure of CRL.
2002402 2025-11-25 GoDaddy: Missing R1 Intermediate Full CRL URLs in CCADB.
2007116 2025-12-19 D-Trust: CRL URL Disclosure.
2007219 2025-12-19 DigiCert: Some certificates issued with CRLDPs that don't exactly match CCADB disclosures.
2007105 2025-12-19 Certum: CRL URLs disclosed in CCADB do not exactly match the CRL URLs in certificates.
2007098 2025-12-19 GlobalSign: misalignment of CRL URL in CCADB with issued certificates.
2007066 2025-12-19 Disig: Missing CA Disig R2I2 Certification Service Full CRL URLs in CCADB.
2007221 2025-12-19 Microsoft PKI Services: recurrence of 1990801.
2007216 2025-12-20 GoDaddy: CRL Disclosure in CCADB Mismatch with Issued Certificates.
2007297 2025-12-21 eMudhra: CRL URL Mismatch Between CCADB Disclosure and Issued Certificates.
2031164 2026-04-12 Google Trust Services: Incomplete CRL Distribution Point URLs in CCADB for GTS Roots.

Root Cause Analysis

Contributing Factor 1: ICA "owner" metadata excluded records from automated CCADB CRL updates

  • Description: DigiCert's automation that updates CRLDP disclosures from our origin to CCADB filters on owner=digicert. Seventeen CAs were configured with owner=quovadis and were therefore excluded from those automated updates, leaving their CRLDP disclosures in CCADB out of synch with updated information in our origin system.
  • Timeline: The owner=quovadis configuration is a legacy from the migration of QuoVadis systems into DigiCert platforms. The exclusion persisted through Bug 2007219, in which these CAs were identified until correction on 2026-07-14 and 2026-07-23.
  • Detection: Detected via a third-party report on 2026-07-13. It avoided earlier detection because our verification during Bug 2007219 was based on accuracy of the origin server not CCADB.
  • Interaction with other factors: The owner-based exclusion masked the affected records from routine automated reconciliation, and flawed alerting on CCADB discrepancies allowed the gap to persist undetected.
  • Root Cause Analysis methodology used: Five Whys.

Contributing Factor 2: Monitoring aligned to the legacy CCADB CRL disclosure model

  • Description: CCADB Policy v2.1 introduced a new "JSON Array of all Full CRL URLs" field and revised the existing "Full CRL Issued By This CA" field. During our investigation, DigiCert found some CCADB CRLs that were incorrectly categorized. DigiCert's monitoring continued to check the legacy disclosure field rather than the new JSON Array.
  • Timeline: The new requirement took effect 2026-03-20. DigiCert's monitoring remained aligned to the legacy field from that date until 2026-07-20.
  • Detection: Identified internally on 2026-07-14 19:21:00 UTC during verification of the "owner" fix.
  • Interaction with other factors: Shares a common systemic cause with CF#3 (policy-change propagation).
  • Root Cause Analysis methodology used: Five Whys.

Contributing Factor 3: CCADB Policy update did not propagate through the standard compliance implementation process

  • Description: DigiCert’s CCADB automation evolved opportunistically as new features were added to the API. The 2026-03-20 CCADB Policy update was not propagated through DigiCert's standard compliance implementation process to all dependent systems, leading to inconsistent implementation.
  • Timeline: Beginning with the 2026-03-20 policy effective date, dependent systems were not updated; the gap persisted until identified on 2026-07-14.
  • Detection: Surfaced on 2026-07-14 during internal verification.
  • Interaction with other factors: This is the upstream systemic factor that gave rise to CF#2 and left CF# 1 uncorrected.
  • Root Cause Analysis methodology used: Five Whys.

Lessons Learned

  • What went well: Both full and partitioned CRL files are maintained and are current with certificate revocations.
  • What didn't go well: The CCADB disclosure issue was discovered by a third-party reporter rather than internally (Action Item 3); the same issue was the subject of Bug 2007219 but were not fully remediated at that time (Action Items 1, 3); the changes required by the 2026-03-20 CCADB Policy update were not propagated to every dependent system (Action Items 2, 3).
  • Where we got lucky: N/A.
  • Additional: The API is a valuable tool for CAs to automate updates to CCADB. DigiCert would welcome organized dialogue about features that would be useful in the CCADB API, and to have a roadmap of future planned changes to allow for implementation.

Action Items

Item Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status
1 Correct the CCADB CRL URL disclosures for the affected CAs. Mitigate CF#1 CCADB records for the 17 CAs match the encoded CRLDP URLs, publicly verifiable via CCADB export. 2026-07-14 Complete
2 Update the CCADB checker/validation to use the new "JSON Array of all Full CRL URLs" field. Prevent / Detect CF#2, CF#3 Monitoring evaluates the JSON Array field; a before/after comparison quantifies and clears all discrepancies. Refresh synched of all CRLDPs in CCADB. 2026-07-25 Complete
3 Update automated alerting to notify compliance and engineering of discrepancies in CCADB. Detect CF#1, CF#2, CF#3 Alerting fires on CCADB discrepancies. 2026-07-31 Ongoing
4 Include CCADB Policy updates in DigiCert's standard compliance update processes. Prevent CF#3 Documented process step, plus evidence that a subsequent CCADB Policy change propagated to all dependent systems. 2026-08-07 Ongoing
5 Propose community engagement in CCADB Policy and API planning. Prevent CF#3 Reach out via public lists or CABF. 2026-08-07 Ongoing

Appendix

The list of 17 CAs is attached.

We will monitor this thread for any comments or questions and kindly ask that the nextUpdate field be set to 2026-08-07.

Flags: needinfo?(incident-reporting)
Flags: needinfo?(incident-reporting)
Whiteboard: [ca-compliance] [disclosure-failure] → [ca-compliance] [disclosure-failure] Next update 2026-08-07

DigiCert has completed Action Item #3 to update alerting of discrepancies between our origin server and CCADB.

DigiCert has completed Action Item #4, formally including CCADB Policy and API updates into our Industry Standards implementation process, coordinating compliance obligations with internal groups.

DigiCert has completed Action Item #5. The topic of CCADB Policy and API planning was discussed in both the CA/Browser Forum NetSec WG (on July 28) and Forum call (on July 30). CCADB administrators also noted that feedback was welcomed at https://groups.google.com/a/ccadb.org/g/public

Report Closure Summary

  • Incident description: On 2026-07-14, DigiCert received a third-party CPR that leaf certificates issued from two DigiCert CAs contained full CRL Distribution Point (CRLDP) URLs beyond those disclosed in the CCADB. Internal investigation identified 15 additional affected CAs (total of 17) whose CRLDP disclosures in the CCADB were incomplete, contrary to CCADB Policy Section 6.2 (v2.0 effective 2025-07-15 and v2.1 effective 2026-03-20). This incident concerned CCADB disclosures only; revocation information remained accurate and available at the disclosed URLs, and no certificate mis-issuance occurred.

  • Incident Root Cause(s): Three contributing factors were identified. (1) 17 CAs carried legacy owner=quovadis metadata from the QuoVadis migration in our systems, which excluded them from DigiCert's automation that synchronizes CRLDP disclosures from our origin system to the CCADB. (2) DigiCert's monitoring remained aligned to the legacy CCADB CRL disclosure field rather than the "JSON Array of all Full CRL URLs" field introduced by CCADB Policy v2.1 because (3) the 2026-03-20 CCADB Policy update was not propagated through DigiCert's standard compliance implementation process to all dependent systems.

  • Remediation description: The CCADB CRLDP disclosures for the affected CAs were corrected, with metatags updated to owner=digicert on 2026-07-14 (6 CAs) and 2026-07-23 (11 CAs), and a full resynchronization of all CRLDPs was verified. DigiCert's CCADB checker and validation were updated to evaluate the "JSON Array of all Full CRL URLs" field, and automated alerting now notifies compliance and engineering of discrepancies between our origin system and CCADB. CCADB updates were formally incorporated into DigiCert's Industry Standards implementation process, and community engagement on CCADB Policy and API planning was raised in the CA/Browser Forum NetSec WG (2026-07-28) and Forum teleconference (2026-07-30). All five Action Items are Complete.

  • Commitment summary: DigiCert will continue automated reconciliation and alerting between our origin systems and the CCADB so that disclosures remain in sync, and will continue to engage with the CCADB community.

All Action Items disclosed in this report have been completed as described, and we request its closure.

Flags: needinfo?(incident-reporting)

This is a final call for comments or questions on this Incident Report.

Otherwise, it will be closed on approximately 2026-08-17.

Flags: needinfo?(incident-reporting)
Whiteboard: [ca-compliance] [disclosure-failure] Next update 2026-08-07 → [close on 2026-8-17] [ca-compliance] [disclosure-failure]
Status: ASSIGNED → RESOLVED
Closed: 19 days ago
Resolution: --- → FIXED
Whiteboard: [close on 2026-8-17] [ca-compliance] [disclosure-failure] → [ca-compliance] [disclosure-failure]
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: