← IdenTrust Services, LLC cases
Bugzilla #1391000 Ca Certificate Compliance Incident Revocation Issue

IdenTrust: Non-BR-Compliant Certificate Issuance

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns certificates issued by IdenTrust that were not compliant with Mozilla Root Store / CA-Browser Forum Baseline Requirements. The initial problems described in the thread included a failure to respond within 24 hours after a Problem Report was submitted, and certificate issues including “pathLenConstraint with CA:FALSE” and an OCSP responder URL that has a HTTPS URI. IdenTrust stated it identified the situation during a routine audit in March 2017, that the certificates were intended to be revoked, but that revocation did not occur due to an informal internal emailed request being overlooked. IdenTrust reported that it revoked the five identified certificates on August 10, 2017 and corrected the certificate profiles since March 2017 to prevent recurrence. Later, Mozilla asked IdenTrust to comment on an additional issue raised in comment #3, and IdenTrust responded that the referenced issues were fully resolved and that remediation was completed as of September 1, 2017, attributing the lack of response to an oversight. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 17:05 UTC Revised: 2026-06-16 19:11 UTC Confidence: 0.86 6 comments
Chronology
  1. IdenTrust identified non-compliant certificates during a routine audit and intended to revoke them, but revocation did not occur.
  2. IdenTrust revoked five identified non-BR-compliant certificates.
  3. IdenTrust completed remediation for the additional issues referenced in the thread.
Thread Activity
  1. Community commenter — Requested information from IdenTrust to continue root store inclusion, citing a failure to respond within 24 hours and certificate issues including pathLenConstraint with CA:FALSE and an OCSP responder URL with a HTTPS URI.
  2. Titanous representative — Posted IdenTrust’s forum reply, stating the issue was reported to IdenTrust on August 9, 2017, addressed on August 10, 2017, listing five affected certificates and explaining that revocation did not occur due to an overlooked informal internal request.
  3. Community commenter — Indicated the response was sufficient.
  4. Titanous representative — Noted an ongoing incident: two IdenTrust ACES intermediates were issuing certificates with a variety of BR violations, with details in another forum thread.
  5. Mozilla representative — Asked IdenTrust to comment on the issue raised in comment #3 and questioned why it had taken a month to respond.
  6. IdenTrust Services, LLC — Stated the referenced issues were fully resolved, remediation was completed as of September 1, 2017, and the lack of response was an oversight.
Participants
Community commenter Titanous representative Mozilla representative IdenTrust Services, LLC
Similar Local Cases
#1792111 RESOLVED Delayed Revocation Incident Opened 2022-09-22 · Closed 2023-02-22 · 90% similar
IdenTrust: Expired CRLs
#1754593 RESOLVED Revocation Issue Opened 2022-02-09 · Closed 2023-02-22 · 89% similar
IdenTrust: Unavailable CRL and OCSP Responders
#1398255 RESOLVED Ca Certificate Compliance Incident Opened 2017-09-08 · Closed 2023-02-22 · 81% similar
IdenTrust: Non-BR-Compliant OCSP Responders
#1536831 RESOLVED Ca Certificate Compliance Revocation Issue Remediation Tracking Opened 2019-03-20 · Closed 2023-02-22 · 72% similar
GDCA: Insufficient Serial Number Entropy
#1523680 RESOLVED Revocation Issue Incident Opened 2019-01-29 · Closed 2023-02-22 · 72% similar
Actalis: Non BR Compliant OCSP Responder
#1853783 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2023-09-18 · Closed 2025-03-20 · 71% similar
IdenTrust: S/MIME certificates issued in violation of New S/MIME Baseline Requirements v1.0
#1321354 RESOLVED Revocation Issue Incident Opened 2016-11-30 · Closed 2022-11-14 · 71% similar
DocuSign France - Internal names certificates under a technically-constrained subordinate CA
#1542082 RESOLVED Incident Self Reported Incident Opened 2019-04-04 · Closed 2023-02-22 · 70% similar
IdenTrust: Failure to disclose Unconstrained intermediate Within 7 Days

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action