← IdenTrust Services, LLC cases
Bugzilla #1446121
Certificate Misissuance
IdenTrust: Improper encoding of wildcard certificate
RESOLVED
FIXED
IdenTrust Services, LLC
AI Summary
IdenTrust faced an issue with improper encoding of wildcard certificates, which was identified during an audit in August 2017. The CA acknowledged the problem and confirmed that it had ceased issuing affected certificates. A formal incident report was provided, detailing the corrective actions taken, including revocation of the impacted certificates by March 2018. IdenTrust has since implemented pre-issuance certificate linting to prevent future occurrences of similar issues.
Chronology
- Configuration problem identified during audit
- All 6 affected certificates revoked
- Pre-issuance certificate linting successfully implemented
Participants
Wayne Thayer
IdenTrust
External References
Similar Local Cases
IdenTrust: Invalid special characters in S/MIME Certificates
IdenTrust: Issuance of Subordinate CA’s Without EKU
IdenTrust: Issuance of OV SSL Certificate with doc vetting older than 398 days
IdenTrust: Internal names / failure to report
IdenTrust: Root OCSP Signer certificate mis-issuance
IdenTrust: CT Logging Mistakes
IdenTrust: test certificates inadvertently published in production environment
IdenTrust: ICA with invalid CDP