Open Bug 2055250 Opened 1 month ago Updated 3 days ago

D-TRUST: Incomplete Disclosure of CRL URLs

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

ASSIGNED

People

(Reporter: Frank.Meissen, Assigned: Frank.Meissen)

Details

(Whiteboard: [ca-compliance] [disclosure-failure] Next update 2026-10-01)

Preliminary Incident Report

Summary

  • Incident description: On 2026-07-13, D-Trust received a Certificate Problem
    Report from a community member stating that HTTP URLs contained in the
    crlDistributionPoints extension of unexpired certificates
    were not disclosed in the "JSON Array of all Full CRL URLs" field of the corresponding CCADB records.
    Our investigation confirmed that URLs were missing at the CCADB records.
    We will update the affected records accordingly.
    Certificate validity is not affected; no revocation is required.
    A Full Incident Report will follow within 14 days.
  • Relevant policies: CCADB Policy, Section 6.2 "Certificate Revocation List
    Disclosures" (https://www.ccadb.org/policy#62-certificate-revocation-list-disclosures)
  • Source of incident disclosure: External – Certificate Problem Report
    received from a community member on 2026-07-13
Assignee: nobody → frank.meissen
Status: UNCONFIRMED → ASSIGNED
Type: defect → task
Ever confirmed: true
Whiteboard: [ca-compliance] [disclosure-failure]
Assignee: frank.meissen → Frank.Meissen

Full Incident Report

Summary
CA Owner CCADB unique ID: A000022
Incident description: D-Trust GmbH was contacted by an external party via a Certificate Problem Report submitted through a web form. The report indicated that certain HTTP URLs contained in the
crlDistributionPoints extension of unexpired certificates were not disclosed in the "JSON Array of all Full CRL URLs" field of the corresponding CCADB records.

Timeline summary:
Non-compliance start date: 2026-03-20
Non-compliance identified date: 2026-07-16
Non-compliance end date: 2026-07-24
Relevant policies: CCADB Policy Version 2.1, Effective: March 20, 2026 6.2 Certificate Revocation List Disclosures
Source of incident disclosure: Third Party Reported

Impact
Total number of certificates: N/A, 31 CCADB entries were affected.
Total number of "remaining valid" certificates: N/A
Affected certificate types: Intermediate CA Certificates
Incident heuristic: N/A. This incident affected CCADB disclosure data rather than issued certificates. The certificates containing the omitted CRL Distribution Point URLs remained valid, and no certificate required revocation. The affected CCADB records and omitted CRL URLs are listed in the Appendix.
Was issuance stopped in response to this incident, and why or why not?: No. Certificate issuance was not impacted, as the issue was limited to CCADB disclosure data and did not affect certificate content, revocation mechanisms or relying party security.
Analysis: N/A, no subscriber certificate have been revoked.
Additional considerations: At all times relying parties were able to retrieve accurate revocation information.

Timeline All Times in UTC
2026-03-20: Automated tool for CCADB checks live
2026-03-20: CCADB Policy Version 2.1 entered into force
2026-07-13 0:35: D-Trust received a certificate problem report regarding Incomplete Disclosure of CRL URLs
2026-07-13 08:34: Reply to sender of Certificate Problem Report
2026-07-13 09:00: Start investigation of the issue
2026-07-24 15:00: Correction of Full CRL URL entries in the CCADB
2026-07-24 20:00: End of investigation
2026-07-29: 20:10 Full Incident Report posted

Related Incidents
Bug Date Description
[2007105] 2025-12-19 Certum: CRL URLs disclosed in CCADB do not exactly match the CRL URLs in certificates.
[2007098] 2025-12-19 GlobalSign: mismatch of CRL URL in CCADB with issued certificate
[2007072] 2025-12-19 TrustAsia: CRL disclosure address using HTTPS instead of HTTP
[2007066]2025-12-19 Disig: missing CRL Distribution Point in CCADB
[2007216] 2025-12-19 GoDaddy: CRL disclosure mismatch between CCADB and issued certificates
[2007297] 2025-12-21 eMudhra: CRL URL mismatch between CCADB disclosure and issued certificates
[2007116] 2025-12-19 D-Trust: CRL URL Disclosure

Root Cause Analysis

  • Contributing Factor #1: Incomplete checks in automated tool for CCADB checks
  • Description: The implemented tool for automated checks did not react as planned. The 2nd CRL-download-URL was not checked for correctness.
  • Timeline: 2026-02-13 - 2026-03-20
  • Detection: Identified following receipt of an external Certificate Problem Report on 13 July 2026
  • Interaction with other factors: N/A
  • Root Cause Analysis methodology used: 5-Why Method

Lessons Learned
What went well: The escalation to compliance security and management.
What didn’t go well: That we did not detect the bug ourselves and that there was the need for an external report. Furhtermore, that the handling of incident #2007116 should have helped prevent this new incident.
Where we got lucky: We were advised by an external source.
Additional: N/A

Action Items
1. Action Item
A change in the CCADB policy will trigger a revision of the configured use cases for the tool, based on a risk-based approach, to ensure that the necessary use cases are covered and possible blind spots are detected. In addition, the revision will be performed periodically - at least once a year.
Kind
prevent
Corresponding Root Cause(s)
Root Cause #1 a
Evaluation Criteria
process description is in place
Due Date
01.10.2026
Status
ongoing

2. Action Item
A regular independent manual check for any entries in the CCADB by a technical specialist accompanying the compliance specialist making the entries in the database upon update will be introduced.
Kind
prevent
Corresponding Root Cause(s)
Root Cause#1
Evaluation Criteria
a process description is in place
Due Date
08.01.2026
Status
done

3. Action Item
We corrected the error for all SubCAs in the CCADB
Kind
mitigate
Corresponding Root Cause(s)
Root Cause#1
Evaluation Criteria
CCADB entries match certificate CRL URLs
Due Date
2026-07-24
Status
done

4. Action Item
A support case was opened through support@ccadb.org in order to be able to correct the Root CAs also.
Kind
mitigate
Corresponding Root Cause(s)
Root Cause#1
Evaluation Criteria
CCADB entries match certificate CRL URLs
Due Date
asap after CCADBD update
Status
ongoing

5. Action Item
We will revise and rework, if necessary, the acceptance process for entries into the CCADB; introducing the acceptance of any entries by the accountable in question.
Kind
prevent
Corresponding Root Cause(s)
Root Cause#1
Evaluation Criteria
a process description is in place
Due Date
08.01.2026
Status
ongoing

Appendix
CA Name incomplete entry in the CCADB extended entry in the CCADB
D-TRUST Root Class 3 CA 2 EV 2009 ["http://crl.d-trust.net/crl/d-trust_root_class_3_ca_2_ev_2009.crl"] ["http://crl.d-trust.net/crl/d-trust_root_class_3_ca_2_ev_2009.crl","http://www.d-trust.net/crl/d-trust_root_class_3_ca_2_ev_2009.crl"]
D-TRUST CA 2-2 EV 2016 ["http://crl.d-trust.net/crl/d-trust_ca_2-2_ev_2016.crl"] ["http://crl.d-trust.net/crl/d-trust_ca_2-2_ev_2016.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust_ca_2-2_ev_2016.crl"]
D-TRUST SSL Class 3 CA 1 EV 2009 ["http://crl.d-trust.net/crl/d-trust_ssl_class_3_ca_1_ev_2009.der.crl"] ["http://crl.d-trust.net/crl/d-trust_ssl_class_3_ca_1_ev_2009.der.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust_ssl_class_3_ca_1_ev_2009.crl"]
D-TRUST Root Class 3 CA 2 2009 ["http://crl.d-trust.net/crl/d-trust_root_class_3_ca_2_2009.crl"] ["http://crl.d-trust.net/crl/d-trust_root_class_3_ca_2_2009.crl","http://www.d-trust.net/crl/d-trust_root_class_3_ca_2_2009.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust_root_class_3_ca_2_2009.crl"]
D-TRUST SSL Class 3 CA 1 2009 ["http://crl.d-trust.net/crl/d-trust_ssl_class_3_ca_1_2009.der.crl"] ["http://crl.d-trust.net/crl/d-trust_ssl_class_3_ca_1_2009.der.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust_ssl_class_3_ca_1_2009.crl"]
D-TRUST SSL CA 2 2020 ["http://crl.d-trust.net/crl/d-trust_ssl_ca_2_2020.crl"] ["http://crl.d-trust.net/crl/d-trust_ssl_ca_2_2020.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust_ssl_ca_2_2020.crl"]
D-TRUST Root CA 3 2013 ["http://crl.d-trust.net/crl/d-trust_root_ca_3_2013.crl"] ["http://crl.d-trust.net/crl/d-trust_root_ca_3_2013.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust_root_ca_3_2013.crl"]
D-TRUST Application Certificates CA 3-1 2013 ["http://crl.d-trust.net/crl/d-trust_application_certificates_ca_3-1_2013.crl"] ["http://crl.d-trust.net/crl/d-trust_application_certificates_ca_3-1_2013.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust_application_certificates_ca_3-1_2013.crl"]
D-TRUST Application Certificates CA 3-2 2016 ["http://crl.d-trust.net/crl/d-trust_application_certificates_ca_3-2_2016.crl"] ["http://crl.d-trust.net/crl/d-trust_application_certificates_ca_3-2_2016.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust_application_certificates_ca_3-2_2016.crl"]
D-TRUST EV Root CA 1 2020 ["http://crl.d-trust.net/crl/d-trust_ev_root_ca_1_2020.crl"] ["http://crl.d-trust.net/crl/d-trust_ev_root_ca_1_2020.crl"]
D-TRUST EV CA 1-20-1 2020 ["http://crl.d-trust.net/crl/d-trust_ev_ca_1-20-1_2020.crl"] ["http://crl.d-trust.net/crl/d-trust_ev_ca_1-20-1_2020.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust_ev_ca_1-20-1_2020.crl"]
D-TRUST BR Root CA 1 2020 ["http://crl.d-trust.net/crl/d-trust_br_root_ca_1_2020.crl"] ["http://crl.d-trust.net/crl/d-trust_br_root_ca_1_2020.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust_br_root_ca_1_2020.crl"]
D-TRUST BR CA 1-20-1 2020 ["http://crl.d-trust.net/crl/d-trust_br_ca_1-20-1_2020.crl"] ["http://crl.d-trust.net/crl/d-trust_br_ca_1-20-1_2020.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust_br_ca_1-20-1_2020.crl"]
D-TRUST BR CA 1-20-2 2020 ["http://crl.d-trust.net/crl/d-trust_br_ca_1-20-2_2020.crl"] ["http://crl.d-trust.net/crl/d-trust_br_ca_1-20-2_2020.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust_br_ca_1-20-2_2020.crl"]
D-TRUST EV CA 2-23-1 2023 ["http://crl.d-trust.net/crl/d-trust_ev_ca_2-23-1_2023.crl"] ["http://crl.d-trust.net/crl/d-trust_ev_ca_2-23-1_2023.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust_ev_ca_2-23-1_2023.crl"]
D-TRUST WR4096 2-23-12 2026 ["http://crl.d-trust.net/crl/d-trust_wr4096_ca_2-23-12_2026.crl"] ["http://crl.d-trust.net/crl/d-trust_wr4096_ca_2-23-12_2026.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust_wr4096_ca_2-23-12_2026.crl"]
D-TRUST WR4096 2-23-22 2026 ["http://crl.d-trust.net/crl/d-trust_wr4096_ca_2-23-22_2026.crl"] ["http://crl.d-trust.net/crl/d-trust_wr4096_ca_2-23-22_2026.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust_wr4096_ca_2-23-22_2026.crl"]
D-TRUST BR Root CA 2 2023 ["http://crl.d-trust.net/crl/d-trust_br_root_ca_2_2023.crl"] ["http://crl.d-trust.net/crl/d-trust_br_root_ca_2_2023.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust_br_root_ca_2_2023.crl"]
D-TRUST BR CA 2-23-1 2023 ["http://crl.d-trust.net/crl/d-trust_br_ca_2-23-1_2023.crl"] ["http://crl.d-trust.net/crl/d-trust_br_ca_2-23-1_2023.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust_br_ca_2-23-1_2023.crl"]
D-TRUST BR CA 2-23-2 2023 ["http://crl.d-trust.net/crl/d-trust_br_ca_2-23-2_2023.crl"] ["http://crl.d-trust.net/crl/d-trust_br_ca_2-23-2_2023.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust_br_ca_2-23-2_2023.crl"]
D-TRUST SCR4096 2-23-31 2026 ["http://crl.d-trust.net/crl/d-trust_scr4096_ca_2-23-31_2026.crl"] ["http://crl.d-trust.net/crl/d-trust_scr4096_ca_2-23-31_2026.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust_scr4096_ca_2-23-31_2026.crl"]
D-Trust SBR CA 1-22-1 2022 ["http://crl.d-trust.net/crl/d-trust_sbr_ca_1-22-1_2022.crl"] ["http://crl.d-trust.net/crl/d-trust_sbr_ca_1-22-1_2022.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust_sbr_ca_1-22-1_2022.crl"]
D-Trust SBR CA 1-22-2 2022 ["http://crl.d-trust.net/crl/d-trust_sbr_ca_1-22-2_2022.crl"] ["http://crl.d-trust.net/crl/d-trust_sbr_ca_1-22-2_2022.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust_sbr_ca_1-22-2_2022.crl"]
D-Trust SBR CA 1-22-3 2023 ["http://crl.d-trust.net/crl/d-trust_sbr_ca_1-22-3_2023.crl"] ["http://crl.d-trust.net/crl/d-trust_sbr_ca_1-22-3_2023.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust_sbr_ca_1-22-3_2023.crl"]
D-Trust SBR CA 1-22-4 2024 ["http://crl.d-trust.net/crl/d-trust_sbr_ca_1-22-4_2024.crl"] ["http://crl.d-trust.net/crl/d-trust_sbr_ca_1-22-4_2024.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust_sbr_ca_1-22-4_2024.crl"]
D-Trust SBR CA 1-22-5 2024 ["http://crl.d-trust.net/crl/d-trust_sbr_ca_1-22-5_2024.crl"] ["http://crl.d-trust.net/crl/d-trust_sbr_ca_1-22-5_2024.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust_sbr_ca_1-22-5_2024.crl"]
D-Trust SBR CA 2-22-1 2022 ["http://crl.d-trust.net/crl/d-trust_sbr_ca_2-22-1_2022.crl"] ["http://crl.d-trust.net/crl/d-trust_sbr_ca_2-22-1_2022.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust_sbr_ca_2-22-1_2022.crl"]
D-Trust SBR CA 2-22-2 2022 ["http://crl.d-trust.net/crl/d-trust_sbr_ca_2-22-2_2022.crl"] ["http://crl.d-trust.net/crl/d-trust_sbr_ca_2-22-2_2022.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust_sbr_ca_2-22-2_2022.crl"]
D-Trust SBR CA 2-22-3 2023 ["http://crl.d-trust.net/crl/d-trust_sbr_ca_2-22-3_2023.crl"] ["http://crl.d-trust.net/crl/d-trust_sbr_ca_2-22-3_2023.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust_sbr_ca_2-22-3_2023.crl"]
D-Trust SBR CA 2-22-4 2024 ["http://crl.d-trust.net/crl/d-trust_sbr_ca_2-22-4_2024.crl"] ["http://crl.d-trust.net/crl/d-trust_sbr_ca_2-22-4_2024.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust_sbr_ca_2-22-4_2024.crl"]
D-Trust SBR CA 2-22-5 2024 ["http://crl.d-trust.net/crl/d-trust_sbr_ca_2-22-5_2024.crl"] ["http://crl.d-trust.net/crl/d-trust_sbr_ca_2-22-5_2024.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust_sbr_ca_2-22-5_2024.crl"]

Action Item #4 status update

Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status
A support case was opened through support@ccadb.org in order to be able to correct the Root CAs also. Mitigate Root Cause # 1 CCADB entries match certificate CRL URLs asap after CCADBD update Completed

Revised Full Incident Report and Action Item clarification

This update clarifies ambiguities and corrects dates / date formats in the Full Incident Report posted on 2026-07-29.

Corrections

  • All dates below use ISO 8601 format (YYYY-MM-DD).
  • Non-compliance identified date: 2026-07-13.
  • Action Item #1 due date: 2026-10-01. Status: Ongoing.
  • Action Item #2 due date: 2026-10-01. Status: Ongoing.
  • Action Item #5 due date: 2026-10-01. Status: Ongoing.

Current Action Item status

# Status Completion or due date Evaluation Criteria
1 Ongoing 2026-10-01 A process has been described and implemented.
2 Ongoing 2026-10-01 A process has been described and implemented.
3 Complete 2026-07-24 CCADB Subordinate CA entries corrected
4 Complete 2026-07-31 Root CA entries corrected through the CCADB support case
5 Ongoing 2026-10-01 Process revision has been performed and possible improvements implemented.

We request that the Next update Whiteboard field be set to 2026-10-01.

Flags: needinfo?(incident-reporting)
Flags: needinfo?(incident-reporting)
Whiteboard: [ca-compliance] [disclosure-failure] → [ca-compliance] [disclosure-failure] Next update 2026-10-01

As part of our review of the proposed closure of Bug 2007116, we identified that the Full Incident Report for this Bug (2055250) does not yet meet the standard we expect for our incident reporting, the current report does not sufficiently describe the root cause and the resulting corrective, preventive, and detective actions.
We therefore believe that this Full Incident Report for should be revised. The revised report will include a more complete root cause analysis and an updated description of the corrective, preventive, and detective actions.
We are currently working on this revision and will provide the updated Full Incident Report shortly.

The Revised Final Incident report will be posted shortly.

Revised Full Incident Report

Summary

  • CA Owner CCADB unique ID: A000022

  • Incident description:
    On 2026-07-13, D-Trust received a Certificate Problem Report indicating that certain HTTP URLs contained in the crlDistributionPoints extension of unexpired certificates were not disclosed in the corresponding CCADB records.

    The investigation confirmed incomplete CRL URL disclosures.

    CRL disclosure was already required before this incident. Under CCADB Policy Version 2.0, effective 2025-07-15, CA Owners were required to disclose either the URL of a full and complete CRL or, where applicable, a JSON array of partitioned CRL URLs. Disclosed URLs were required to exactly match URLs appearing in certificates issued by the corresponding CA.

    CCADB Policy Version 2.1, effective 2026-03-20, changed Section 6.2 to require disclosure of the complete set of distinct HTTP URLs appearing in the crlDistributionPoints extension of unexpired certificates issued by the corresponding CA.

    When Policy Version 2.1 became effective, D-Trust's CCADB records and automated reconciliation control did not account for every Full CRL URL required by the updated disclosure requirement. Consequently, the incomplete disclosures were not detected internally. The causal analysis below examines how the external requirement was converted into internal requirements, implementation work, acceptance evidence, and ongoing verification.

  • Timeline summary:

    • Non-compliance start date: 2026-03-20
    • Non-compliance identified date: 2026-07-13
    • Non-compliance end date: 2026-07-31
  • Relevant policies:

    • CCADB Policy Version 2.1, effective 2026-03-20
    • Section 1, General Provisions
    • Section 6.2, Certificate Revocation List Disclosures
  • Source of incident disclosure: Third Party Reported

Impact

  • Total number of certificates: N/A. This incident concerned CCADB disclosure data rather than non-compliant certificate issuance. 30 CCADB CA certificate records were affected.

  • Total number of "remaining valid" certificates: N/A.

  • Affected certificate types: N/A. The affected CCADB records corresponded to Root and Subordinate CA certificates. The contents of the certificates themselves were not affected.

  • Incident heuristic: N/A. The complete list of affected CCADB records is provided in the Appendix.

  • Was issuance stopped in response to this incident, and why or why not?:
    No. The non-compliance concerned CCADB disclosure data. Stopping certificate issuance would not have corrected the incomplete CCADB records.

  • Analysis: N/A. The incident did not require revocation of certificates.

  • Additional considerations:
    Based on validation performed during the investigation, at least one Full CRL URL already disclosed for each affected record remained reachable and provided the applicable current CRL throughout the incident. The missing CCADB values represented additional HTTP distribution paths appearing in certificates issued by the corresponding CA. Relying parties therefore retained access to revocation information despite the incomplete CCADB disclosures. This operational circumstance did not remove or reduce the disclosure non-compliance.

    Under CCADB Policy Version 2.0, disclosure of one qualifying full and complete CRL URL was sufficient where partitioned CRLs were not used. As part of the CCADB update supporting Policy Version 2.1, the value from the existing Full CRL Issued By This CA field was used to populate the new JSON Array of all Full CRL URLs field. D-Trust did not subsequently add all additional distinct Full CRL URLs required by Version 2.1.

    An earlier version of this incident report stated that 31 CCADB records were affected. Revalidation determined that one record previously included in that count, D-TRUST EV Root CA 1 2020, had identical incomplete and corrected values and was not affected. The corrected number of affected CCADB records is 30.

Timeline

All times are UTC unless otherwise stated.

  • 2025-07-15: CCADB Policy Version 2.0 became effective. Section 6.2 required, for each applicable CA certificate record, disclosure of either a full and complete CRL URL or a JSON array of partitioned CRL URLs. Disclosed URLs were required to exactly match URLs appearing in certificates issued by the corresponding CA.
  • 2025-12-18: D-Trust became aware of the CRL URL disclosure issue subsequently documented in Bug 2007116.
  • 2026-01-23: The CCADB Steering Committee requested feedback on proposed policy updates. The announcement identified a proposed Full CRL field containing the complete set of distinct HTTP URLs appearing in the crlDistributionPoints extension of unexpired certificates issued by the corresponding CA.
  • 2026-02-01: The action item in Bug 2007116 concerning advanced control validation for policy updates was reported as completed.
  • 2026-02-13 to 2026-03-20: D-Trust implemented an automated reconciliation control for CCADB certificate-related data.
  • 2026-03-16: The CCADB Steering Committee announced the CCADB update supporting multiple Full CRL URLs. The announcement described the new JSON Array of all Full CRL URLs field, stated that existing values would be migrated from the previous Full CRL Issued By This CA field, and stated that CA Owners would be responsible for maintaining the new field after migration. The announcement also stated that a copy would be sent to all CA Owners.
  • 2026-03-20: CCADB Policy Version 2.1 was published and became effective. Section 6.2 required disclosure of the complete set of distinct HTTP URLs appearing in the crlDistributionPoints extension of unexpired certificates issued by the corresponding CA, including when only one full CRL was used.
  • 2026-03-20: The CCADB system update supporting multiple Full CRL URLs was completed. Existing Full CRL Issued By This CA values were used to populate the new JSON Array of all Full CRL URLs field.
  • 2026-03-20: D-Trust's automated CCADB reconciliation control went live. Its implemented requirements and test cases did not verify the complete set of distinct Full CRL URLs required by Policy Version 2.1. Consequently, the control did not detect the incomplete disclosures.
  • 2026-07-13 00:35: D-Trust received a Certificate Problem Report regarding incomplete disclosure of CRL URLs.
  • 2026-07-13 08:34: D-Trust replied to the reporter.
  • 2026-07-13 09:00: Investigation of the issue started.
  • 2026-07-24 15:00: The affected Subordinate CA CCADB records were corrected.
  • 2026-07-24 20:00: The initial investigation and remediation of directly editable CCADB records were completed.
  • 2026-07-29 20:10: The first Full Incident Report was posted.
  • 2026-07-31: The affected Root CA CCADB records were corrected through the CCADB support process.
  • 2026-08-07: Corrections to dates, date formats, and action item status information were posted.
  • 2026-08-14: Review of the report identified that the initial Root Cause Analysis, the description of the corrective, preventive, and detective actions, and the affected-record count required revision.

Related Incidents

Bug Date Description
Bug 2007105 2025-12-19 Certum incident involving CRL URLs disclosed in CCADB that did not exactly match URLs in certificates.
Bug 2007098 2025-12-19 GlobalSign incident involving a mismatch between CCADB CRL URL disclosures and issued certificates.
Bug 2007072 2025-12-19 TrustAsia incident involving an incorrect CRL URL disclosure.
Bug 2007066 2025-12-19 Disig incident involving missing CRL Distribution Point information in CCADB.
Bug 2007216 2025-12-19 GoDaddy incident involving differences between CCADB CRL disclosures and issued certificates.
Bug 2007297 2025-12-21 eMudhra incident involving CRL URL disclosure differences.
Bug 2007116 2025-12-19 Earlier D-Trust CRL URL disclosure incident. Its remediation included policy-change validation and reconciliation between certificate data and CCADB records.

Root Cause Analysis

Contributing Factor #1: The external requirement change was not completed through an evidence-based requirements lifecycle before its effective date

  • Description:
    Policy Version 2.1 changed the applicable disclosure requirement from one qualifying Full CRL URL to the complete set of distinct HTTP Full CRL URLs appearing in unexpired certificates issued by the corresponding CA.

    The change was publicly proposed on 2026-01-23, operationally announced on 2026-03-16, and published as effective on 2026-03-20. The applicable change did not result in completed updates to D-Trust's existing CCADB records, maintenance procedure, reconciliation requirements, and verification evidence before the effective date.

    The policy-change validation measure introduced after Bug 2007116 did not provide effective end-to-end evidence that this change had been assessed, converted into tracked implementation work, completed, and independently verified before it became effective.

  • Timeline:
    The contributing condition existed before 2026-03-20. It resulted in non-compliance when Policy Version 2.1 became effective and continued until the incomplete disclosures were identified on 2026-07-13.

  • Detection:
    The condition was identified during the investigation following the external Certificate Problem Report. It was not detected earlier because the applicable requirements baseline and completion evidence did not demonstrate implementation of the new completeness requirement.

  • Interaction with other factors:
    This factor allowed both the CCADB maintenance activity and the reconciliation control to operate against an incomplete requirements baseline. Contributing Factor #2 did not independently detect and contain that deficiency.

  • Root Cause Analysis methodology used: Five Whys, applied as a causal chain

    1. Why were additional Full CRL URLs absent from the CCADB records?
      The records contained the previously disclosed Full CRL URL, but the additional distinct HTTP Full CRL URLs appearing in unexpired certificates were not added.
    2. Why were the additional URLs not added before Policy Version 2.1 became effective?
      The new complete-set requirement was not incorporated into the CCADB maintenance requirements and completed as tracked implementation work before the effective date.
    3. Why was the requirement not completed as tracked implementation work?
      The external policy change did not progress through an effective end-to-end path covering impact assessment, implementation, testing, and verification.
    4. Why did the end-to-end path not ensure completion?
      The process did not require sufficient traceability evidence linking each applicable external requirement to completed changes in records, procedures, controls, and tests.
    5. Why could the change be treated as processed without that evidence?
      The completion criteria for external policy changes did not require a final, independently verified demonstration that every applicable requirement had been implemented before its effective date.

Contributing Factor #2: The reconciliation control's design and acceptance evidence did not cover complete-set validation

  • Description:
    The automated reconciliation control went live on the same date that Policy Version 2.1 became effective. The implemented control did not compare the complete set of distinct HTTP Full CRL URLs derived from applicable unexpired certificates with the complete set disclosed in the corresponding CCADB record.

    The control could therefore operate successfully against its configured use cases while remaining unable to detect the omission reported in this incident.

  • Timeline:
    The control was implemented between 2026-02-13 and 2026-03-20 and went live on 2026-03-20. The coverage gap remained until the issue was externally reported on 2026-07-13.

  • Detection:
    The coverage gap was identified during the incident investigation. It avoided earlier detection because design review, acceptance testing, and independent review did not compare the complete certificate-derived URL set with the complete CCADB-disclosed set. They also did not require a negative test in which one of multiple Full CRL URLs was missing from the CCADB.

  • Interaction with other factors:
    Contributing Factor #1 provided an incomplete requirements baseline. This factor allowed the resulting incomplete control behavior to be accepted and deployed without an independent current-policy coverage check.

  • Root Cause Analysis methodology used: Five Whys, applied as a separate causal chain

    1. Why did the reconciliation control not alert on the incomplete disclosures?
      The control did not verify the complete set of distinct Full CRL URLs.
    2. Why did the control not perform complete-set validation?
      Its implemented requirements, use cases, and tests did not include the Policy Version 2.1 completeness requirement.
    3. Why was the coverage gap not identified before go-live?
      Acceptance did not require traceability from the policy effective at go-live to each implemented control use case and test case.
    4. Why did acceptance not require that traceability?
      The control lifecycle did not include an effective independent gate for current-policy coverage and negative testing before production deployment.
    5. Why could the control be accepted without demonstrating current-policy coverage?
      The external-requirements process and the control-acceptance process did not share a single evidence-based completion criterion.

Lessons Learned

  • What went well:
    The external report was promptly escalated to the relevant compliance, security, technical, and management functions. Investigation started on the same day. Directly editable Subordinate CA records were corrected, and the remaining Root CA records were subsequently corrected through the CCADB support process.

  • What didn’t go well:

    • Applicable external requirement changes were not completed through implementation and verification before their effective dates.
    • The automated reconciliation control did not verify the complete set of Full CRL URLs required by the current CCADB Policy.
    • The remediation implemented following Bug 2007116 did not provide effective end-to-end evidence that external requirements had been assessed, implemented, tested, and verified.
    • The implementation and acceptance process did not detect that the control's requirements and tests omitted an applicable requirement.
    • The initial incident report did not include an adequate systemic RCA and described the immediate control defect as the contributing factor.
    • The initial incident report overstated the affected-record count because the summary and appendix were not sufficiently reconciled and independently verified before publication.
  • Where we got lucky:
    Based on validation performed during the investigation, at least one Full CRL URL already disclosed for each affected record remained reachable and provided the applicable current CRL throughout the incident. The missing values were additional distribution paths, so relying parties retained access to revocation information despite the incomplete disclosures. This circumstance cannot be relied upon as a control and did not change the disclosure requirement.

  • Additional:
    Bug 2007116 demonstrated the importance of validating CCADB information against certificate data. This incident showed that technical reconciliation cannot compensate for an incomplete requirements baseline, and that a control cannot be considered effective solely because it passes the use cases against which it was designed. External requirement changes, control acceptance, and ongoing assurance need shared traceability and evidence-based completion criteria.

Action Items

Nr Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status
1 Improve the external requirements change process. Prevent Contributing Factor #1 For each external change, a process is triggered that entails an assessment and update of the procedure for the CCADB value entry population. A versioned record links the requirement and effective date to its impact assessment, implementation tasks, independent verification, and closure. 2026-10-01 Ongoing
2 Expand reconciliation controls to validate complete data sets. Prevent Contributing Factor #1 & #2 For the updated procedure described in Action Item 1, positive and negative tests detect missing, unexpected, and malformed values when comparing authoritative internal data with external disclosures. Testing includes the complete Full CRL URL set required by CCADB Policy Version 2.1. Production checks identify no unexplained differences. A second review confirms the results before “go live”. 2026-10-01 Ongoing
3 Correct all affected CCADB records. Mitigate Contributing Factor #1 All 30 affected records disclose the complete CRL URL information required by CCADB Policy Version 2.1. 2026-07-31 Complete
4 Add incident-report verification. Prevent What didn’t go well: report accuracy Before publication, a second reviewer verifies dates, totals, affected-record lists, sample evidence, action status, and internal consistency of the Incident Report before it is published. 2026-10-01 Ongoing

Appendix

The following 30 CCADB CA certificate records were affected. The table shows the incomplete value previously stored in the CCADB and the complete value after remediation.

An earlier version of this report stated that 31 records were affected. Revalidation determined that D-TRUST EV Root CA 1 2020, which had previously been included in the count, had identical incomplete and corrected values and was therefore not affected by this incident.

The following 30 CCADB CA certificate records were affected. The table shows the incomplete value previously stored in the CCADB and the complete value after remediation.

CA Certificate Record Incomplete entry in the CCADB Complete entry in the CCADB
D-TRUST Root Class 3 CA 2 EV 2009 \["http://crl.d-trust.net/crl/d-trust\_root\_class\_3\_ca\_2\_ev\_2009.crl"] \["http://crl.d-trust.net/crl/d-trust\_root\_class\_3\_ca\_2\_ev\_2009.crl","http://www.d-trust.net/crl/d-trust\_root\_class\_3\_ca\_2\_ev\_2009.crl"]
D-TRUST CA 2-2 EV 2016 \["http://crl.d-trust.net/crl/d-trust\_ca\_2-2\_ev\_2016.crl"] \["http://crl.d-trust.net/crl/d-trust\_ca\_2-2\_ev\_2016.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust\_ca\_2-2\_ev\_2016.crl"]
D-TRUST SSL Class 3 CA 1 EV 2009 \["http://crl.d-trust.net/crl/d-trust\_ssl\_class\_3\_ca\_1\_ev\_2009.der.crl"] \["http://crl.d-trust.net/crl/d-trust\_ssl\_class\_3\_ca\_1\_ev\_2009.der.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust\_ssl\_class\_3\_ca\_1\_ev\_2009.crl"]
D-TRUST Root Class 3 CA 2 2009 \["http://crl.d-trust.net/crl/d-trust\_root\_class\_3\_ca\_2\_2009.crl"] \["http://crl.d-trust.net/crl/d-trust\_root\_class\_3\_ca\_2\_2009.crl","http://www.d-trust.net/crl/d-trust\_root\_class\_3\_ca\_2\_2009.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust\_root\_class\_3\_ca\_2\_2009.crl"]
D-TRUST SSL Class 3 CA 1 2009 \["http://crl.d-trust.net/crl/d-trust\_ssl\_class\_3\_ca\_1\_2009.der.crl"] \["http://crl.d-trust.net/crl/d-trust\_ssl\_class\_3\_ca\_1\_2009.der.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust\_ssl\_class\_3\_ca\_1\_2009.crl"]
D-TRUST SSL CA 2 2020 \["http://crl.d-trust.net/crl/d-trust\_ssl\_ca\_2\_2020.crl"] \["http://crl.d-trust.net/crl/d-trust\_ssl\_ca\_2\_2020.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust\_ssl\_ca\_2\_2020.crl"]
D-TRUST Root CA 3 2013 \["http://crl.d-trust.net/crl/d-trust\_root\_ca\_3\_2013.crl"] \["http://crl.d-trust.net/crl/d-trust\_root\_ca\_3\_2013.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust\_root\_ca\_3\_2013.crl"]
D-TRUST Application Certificates CA 3-1 2013 \["http://crl.d-trust.net/crl/d-trust\_application\_certificates\_ca\_3-1\_2013.crl"] \["http://crl.d-trust.net/crl/d-trust\_application\_certificates\_ca\_3-1\_2013.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust\_application\_certificates\_ca\_3-1\_2013.crl"]
D-TRUST Application Certificates CA 3-2 2016 \["http://crl.d-trust.net/crl/d-trust\_application\_certificates\_ca\_3-2\_2016.crl"] \["http://crl.d-trust.net/crl/d-trust\_application\_certificates\_ca\_3-2\_2016.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust\_application\_certificates\_ca\_3-2\_2016.crl"]
D-TRUST EV CA 1-20-1 2020 \["http://crl.d-trust.net/crl/d-trust\_ev\_ca\_1-20-1\_2020.crl"] \["http://crl.d-trust.net/crl/d-trust\_ev\_ca\_1-20-1\_2020.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust\_ev\_ca\_1-20-1\_2020.crl"]
D-TRUST BR Root CA 1 2020 \["http://crl.d-trust.net/crl/d-trust\_br\_root\_ca\_1\_2020.crl"] \["http://crl.d-trust.net/crl/d-trust\_br\_root\_ca\_1\_2020.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust\_br\_root\_ca\_1\_2020.crl"]
D-TRUST BR CA 1-20-1 2020 \["http://crl.d-trust.net/crl/d-trust\_br\_ca\_1-20-1\_2020.crl"] \["http://crl.d-trust.net/crl/d-trust\_br\_ca\_1-20-1\_2020.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust\_br\_ca\_1-20-1\_2020.crl"]
D-TRUST BR CA 1-20-2 2020 \["http://crl.d-trust.net/crl/d-trust\_br\_ca\_1-20-2\_2020.crl"] \["http://crl.d-trust.net/crl/d-trust\_br\_ca\_1-20-2\_2020.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust\_br\_ca\_1-20-2\_2020.crl"]
D-TRUST EV CA 2-23-1 2023 \["http://crl.d-trust.net/crl/d-trust\_ev\_ca\_2-23-1\_2023.crl"] \["http://crl.d-trust.net/crl/d-trust\_ev\_ca\_2-23-1\_2023.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust\_ev\_ca\_2-23-1\_2023.crl"]
D-TRUST WR4096 2-23-12 2026 \["http://crl.d-trust.net/crl/d-trust\_wr4096\_ca\_2-23-12\_2026.crl"] \["http://crl.d-trust.net/crl/d-trust\_wr4096\_ca\_2-23-12\_2026.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust\_wr4096\_ca\_2-23-12\_2026.crl"]
D-TRUST WR4096 2-23-22 2026 \["http://crl.d-trust.net/crl/d-trust\_wr4096\_ca\_2-23-22\_2026.crl"] \["http://crl.d-trust.net/crl/d-trust\_wr4096\_ca\_2-23-22\_2026.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust\_wr4096\_ca\_2-23-22\_2026.crl"]
D-TRUST BR Root CA 2 2023 \["http://crl.d-trust.net/crl/d-trust\_br\_root\_ca\_2\_2023.crl"] \["http://crl.d-trust.net/crl/d-trust\_br\_root\_ca\_2\_2023.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust\_br\_root\_ca\_2\_2023.crl"]
D-TRUST BR CA 2-23-1 2023 \["http://crl.d-trust.net/crl/d-trust\_br\_ca\_2-23-1\_2023.crl"] \["http://crl.d-trust.net/crl/d-trust\_br\_ca\_2-23-1\_2023.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust\_br\_ca\_2-23-1\_2023.crl"]
D-TRUST BR CA 2-23-2 2023 \["http://crl.d-trust.net/crl/d-trust\_br\_ca\_2-23-2\_2023.crl"] \["http://crl.d-trust.net/crl/d-trust\_br\_ca\_2-23-2\_2023.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust\_br\_ca\_2-23-2\_2023.crl"]
D-TRUST SCR4096 2-23-31 2026 \["http://crl.d-trust.net/crl/d-trust\_scr4096\_ca\_2-23-31\_2026.crl"] \["http://crl.d-trust.net/crl/d-trust\_scr4096\_ca\_2-23-31\_2026.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust\_scr4096\_ca\_2-23-31\_2026.crl"]
D-Trust SBR CA 1-22-1 2022 \["http://crl.d-trust.net/crl/d-trust\_sbr\_ca\_1-22-1\_2022.crl"] \["http://crl.d-trust.net/crl/d-trust\_sbr\_ca\_1-22-1\_2022.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust\_sbr\_ca\_1-22-1\_2022.crl"]
D-Trust SBR CA 1-22-2 2022 \["http://crl.d-trust.net/crl/d-trust\_sbr\_ca\_1-22-2\_2022.crl"] \["http://crl.d-trust.net/crl/d-trust\_sbr\_ca\_1-22-2\_2022.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust\_sbr\_ca\_1-22-2\_2022.crl"]
D-Trust SBR CA 1-22-3 2023 \["http://crl.d-trust.net/crl/d-trust\_sbr\_ca\_1-22-3\_2023.crl"] \["http://crl.d-trust.net/crl/d-trust\_sbr\_ca\_1-22-3\_2023.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust\_sbr\_ca\_1-22-3\_2023.crl"]
D-Trust SBR CA 1-22-4 2024 \["http://crl.d-trust.net/crl/d-trust\_sbr\_ca\_1-22-4\_2024.crl"] \["http://crl.d-trust.net/crl/d-trust\_sbr\_ca\_1-22-4\_2024.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust\_sbr\_ca\_1-22-4\_2024.crl"]
D-Trust SBR CA 1-22-5 2024 \["http://crl.d-trust.net/crl/d-trust\_sbr\_ca\_1-22-5\_2024.crl"] \["http://crl.d-trust.net/crl/d-trust\_sbr\_ca\_1-22-5\_2024.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust\_sbr\_ca\_1-22-5\_2024.crl"]
D-Trust SBR CA 2-22-1 2022 \["http://crl.d-trust.net/crl/d-trust\_sbr\_ca\_2-22-1\_2022.crl"] \["http://crl.d-trust.net/crl/d-trust\_sbr\_ca\_2-22-1\_2022.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust\_sbr\_ca\_2-22-1\_2022.crl"]
D-Trust SBR CA 2-22-2 2022 \["http://crl.d-trust.net/crl/d-trust\_sbr\_ca\_2-22-2\_2022.crl"] \["http://crl.d-trust.net/crl/d-trust\_sbr\_ca\_2-22-2\_2022.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust\_sbr\_ca\_2-22-2\_2022.crl"]
D-Trust SBR CA 2-22-3 2023 \["http://crl.d-trust.net/crl/d-trust\_sbr\_ca\_2-22-3\_2023.crl"] \["http://crl.d-trust.net/crl/d-trust\_sbr\_ca\_2-22-3\_2023.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust\_sbr\_ca\_2-22-3\_2023.crl"]
D-Trust SBR CA 2-22-4 2024 \["http://crl.d-trust.net/crl/d-trust\_sbr\_ca\_2-22-4\_2024.crl"] \["http://crl.d-trust.net/crl/d-trust\_sbr\_ca\_2-22-4\_2024.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust\_sbr\_ca\_2-22-4\_2024.crl"]
D-Trust SBR CA 2-22-5 2024 \["http://crl.d-trust.net/crl/d-trust\_sbr\_ca\_2-22-5\_2024.crl"] \["http://crl.d-trust.net/crl/d-trust\_sbr\_ca\_2-22-5\_2024.crl","http://cdn.d-trust-cloudcrl.net/crl/d-trust\_sbr\_ca\_2-22-5\_2024.crl"]

D-Trust confirms that the reported Action Items are ongoing and the due dates remain unchanged.

We therefore request the "Next update" Whiteboard field to be set to the date of 2026-10-01

You need to log in before you can comment on or make changes to this bug.