IdenTrust: Non-BR-Compliant Certificate Issuance
This case concerns certificates issued by IdenTrust that were not compliant with Mozilla Root Store / CA-Browser Forum Baseline Requirements. The initial problems described in the thread included a failure to respond within 24 hours after a Problem Report was submitted, and certificate issues including “pathLenConstraint with CA:FALSE” and an OCSP responder URL that has a HTTPS URI. IdenTrust stated it identified the situation during a routine audit in March 2017, that the certificates were intended to be revoked, but that revocation did not occur due to an informal internal emailed request being overlooked. IdenTrust reported that it revoked the five identified certificates on August 10, 2017 and corrected the certificate profiles since March 2017 to prevent recurrence. Later, Mozilla asked IdenTrust to comment on an additional issue raised in comment #3, and IdenTrust responded that the referenced issues were fully resolved and that remediation was completed as of September 1, 2017, attributing the lack of response to an oversight. The bug is marked RESOLVED with resolution FIXED.
- IdenTrust identified non-compliant certificates during a routine audit and intended to revoke them, but revocation did not occur.
- IdenTrust revoked five identified non-BR-compliant certificates.
- IdenTrust completed remediation for the additional issues referenced in the thread.
- Community commenter — Requested information from IdenTrust to continue root store inclusion, citing a failure to respond within 24 hours and certificate issues including pathLenConstraint with CA:FALSE and an OCSP responder URL with a HTTPS URI.
- Titanous representative — Posted IdenTrust’s forum reply, stating the issue was reported to IdenTrust on August 9, 2017, addressed on August 10, 2017, listing five affected certificates and explaining that revocation did not occur due to an overlooked informal internal request.
- Community commenter — Indicated the response was sufficient.
- Titanous representative — Noted an ongoing incident: two IdenTrust ACES intermediates were issuing certificates with a variety of BR violations, with details in another forum thread.
- Mozilla representative — Asked IdenTrust to comment on the issue raised in comment #3 and questioned why it had taken a month to respond.
- IdenTrust Services, LLC — Stated the referenced issues were fully resolved, remediation was completed as of September 1, 2017, and the lack of response was an oversight.