← IdenTrust Services, LLC cases
Bugzilla #1305582 Ca Documents

IdenTrust - Updated 2016 WebTrust Reports

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns IdenTrust submitting updated WebTrust audit reports for its Mozilla-included root CAs. The bug was opened by IdenTrust (r**********s@identrust.com) stating that IdenTrust completed its WebTrust audit and that auditors have complete reports. The roots listed as audited and in the Mozilla program are DST ACES CA X6, DST Root CA X3, IdenTrust Public Sector Root CA 1, and IdenTrust Commercial Root CA 1, with links to WebTrust for CA version 2.0 and WebTrust for Baseline Requirements. Mozilla staff asked whether issues referenced in another bug (1037590#c22 and #c23) should have been called out in this audit report. IdenTrust’s assigned contact responded that it was not clear what subCAs were audited and suggested that expectations should be set via the CA/Browser Forum for audit statements to clearly identify which root and intermediate certificates were covered. The assigned contact also updated the Common CA Database with the 2016 audit information. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 14:05 UTC Revised: 2026-06-16 19:10 UTC Confidence: 0.86 4 comments
Chronology
  1. IdenTrust submitted updated 2016 WebTrust audit report information for its Mozilla-included root CAs.
  2. Mozilla questioned whether previously noted issues should have been reflected in the submitted audit report.
  3. IdenTrust clarified concerns about which subCAs were covered and updated CA Community/CCADB with the 2016 audit info.
Thread Activity
  1. IdenTrust Services, LLC — Opened the bug stating IdenTrust completed its WebTrust audit and provided links, listing the audited roots in the Mozilla program.
  2. Community commenter — Asked whether the issues from bug 1037590#c22 and #c23 should have been called out in this audit report.
  3. Mozilla representative — Responded that it was unclear what subCAs were audited and proposed setting CA/Browser Forum expectations for audit statements to identify covered roots and intermediates.
  4. Mozilla representative — Stated that the Common CA Database (CA Community in Salesforce) was updated with the 2016 audit information.
Participants
IdenTrust Services, LLC Community commenter
Related Bugzilla IDs Mentioned
Similar Local Cases
#1588213 RESOLVED Ca Documents Audit Finding Opened 2019-10-11 · Closed 2024-06-30 · 97% similar
IdenTrust: Missing Thumbprints for Intermediate CA certificates In Some Annual Audit Reports
#1337036 RESOLVED Ca Documents Opened 2017-02-06 · Closed 2022-12-08 · 80% similar
Audit infor for IdenTrust Commercial Root CA 1_EV SSL
#1581597 RESOLVED Ca Documents Audit Finding Opened 2019-09-16 · Closed 2023-02-22 · 68% similar
QuoVadis: Unconstrained CAs missing audits
#1565270 RESOLVED Ca Documents Opened 2019-07-11 · Closed 2023-02-22 · 68% similar
Telia: Qualified BR Audit Statement
#1549862 RESOLVED Ca Documents Audit Finding Opened 2019-05-07 · Closed 2023-02-22 · 68% similar
Entrust: Outdated audit statement for intermediate cert
#1606380 RESOLVED Ca Documents Opened 2019-12-30 · Closed 2023-02-22 · 68% similar
Firmaprofesional: 2019 Audit Report Findings
#1320827 RESOLVED Ca Documents Opened 2016-11-28 · Closed 2022-12-08 · 67% similar
TrustCor Audit info
#1472993 RESOLVED Ca Documents Audit Document Opened By Ca Single Ca Owner Opened 2018-07-03 · Closed 2026-07-01 · 67% similar
Sectigo audit reports

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action