Quality of CCADB "Test Website - Revoked" field

302 views
Skip to first unread message

Joe Birr-Pixton

unread,
Dec 29, 2025, 7:47:33 AM12/29/25
to CCADB Public

Hello,


Just thought I'd report some findings about the quality of the "Test Website - Revoked" field values. This is in the context of using this data for testing revocation software. Please let me know if there is a more suitable venue for this, thanks!


Certificate is not actually revoked (probably because it is also expired):

(both of these have a single CRL referenced in their CRLDP extension, and they are valid and fresh but also empty. Most likely because the certs are also expired, see below.)


CRL is outdated:


Not in CT (realize this is not required by BRs, but would be nice if these sites were otherwise accepted by browsers except for being revoked):


Fails to handshake with rustls, openssl 3, boringssl and firefox:


Certificate is expired because server is configured with wrong certificate: replies with certificate for expired4ktlsr2022.affirmtrust.com


Certificate is expired:


Server is misconfigured and does not include intermediate certificates:


CRL DP server quoted in issuer not working:


Thanks,

Joe


Matthew McPherrin

unread,
Jan 6, 2026, 11:18:36 PMJan 6
to Joe Birr-Pixton, CCADB Public
Those Microsoft roots look like they're not trusted by any of (Apple, Chrome, Microsoft, Mozilla), so you might want to filter out roots which are no longer trusted by anyone.

Same with the AffirmTrust, Entrust, though they don't look fully distrusted from CCADB alone (at least at a quick glance)

I'd encourage you to submit a Certificate Problem Report to Actalis.

I'm seeing a certificate chain being served by Kamu SM, though it includes the unnecessary self-signed root in the chain - too many entries, not too few.

--
You received this message because you are subscribed to the Google Groups "CCADB Public" group.
To unsubscribe from this group and stop receiving emails from it, send an email to public+un...@ccadb.org.
To view this discussion visit https://groups.google.com/a/ccadb.org/d/msgid/public/bd10d8e5-84c6-49fe-a776-9ef23ed5a4bfn%40ccadb.org.
Reply all
Reply to author
Forward
0 new messages