← IdenTrust Services, LLC cases
Bugzilla #1500593 Self Reported Incident Certificate Misissuance

IdenTrust: Internal names / failure to report

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The case concerns an Identrust TLS certificate that contained SAN entries for invalid “.int” domains. Nicholas Hatch reported the misissuance during discussion of an inclusion request in bug 1339292, and Identrust acknowledged the issue and revoked the certificate in a timely manner. Identrust stated that it became aware of the problem on 02/22/2018 via an email message to its customer support from Nicholas Hatch, and that the certificate was revoked on the same date. Identrust reported that only one certificate was found with a SAN containing “.int”, and that it was issued on 5/21/2015 and revoked on 2/22/2018. Identrust explained that the certificate was generated for an internal server and that the “.int” SAN entries were internal domains at the time; after identification, Identrust revoked the certificate and issued a new one without the “Autodiscover.identrus.int” and “Mercury.identrus.int” entries. Identrust also stated that it implemented a change in its certificate approval processes after 02/22/2018 to prevent “.int” domain names from being approved. The bug was resolved as FIXED, and the discussion was noted to have resulted in denial of an EV request in bug 1339292.

Model: gpt-5.4-nano Generated: 2026-06-13 17:55 UTC Revised: 2026-06-16 19:13 UTC Confidence: 0.86 2 comments
Chronology
  1. A misissued certificate containing SAN entries for invalid .int domains was reported to Identrust.
  2. IdenTrust revoked the certificate and reported remediation steps, including process changes to prevent .int SAN entries.
  3. Thread noted that the discussion resulted in denial of an EV request in bug 1339292.
Thread Activity
  1. Fastly representative — Wayne Thayer described the reported misissuance and stated that Identrust acknowledged and revoked the certificate, but he questioned whether Identrust disclosed the misissuance as required; Identrust provided an incident report with awareness date, revocation date, certificate list, explanation, and remediation/process changes.
  2. Fastly representative — Wayne Thayer noted that the discussion resulted in denial of the EV request in bug 1339292.
Participants
Fastly representative IdenTrust Services, LLC Community commenter
Related Bugzilla IDs Mentioned
Similar Local Cases
#1930029 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-11-08 · Closed 2025-02-19 · 98% similar
IdenTrust: Approval of TLS certificate renewal without domain validation
#2014609 RESOLVED Self Reported Incident Certificate Misissuance Opened 2026-02-05 · Closed 2026-04-11 · 98% similar
IdenTrust: Cross-signed root certificate mis-issuance
#1853783 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2023-09-18 · Closed 2025-03-20 · 97% similar
IdenTrust: S/MIME certificates issued in violation of New S/MIME Baseline Requirements v1.0
#1910195 RESOLVED Certificate Misissuance Self Reported Incident Opened 2024-07-26 · Closed 2024-09-06 · 97% similar
IdenTrust: Invalid special characters in S/MIME Certificates
#2026351 RESOLVED Self Reported Incident Certificate Misissuance Opened 2026-03-25 · Closed 2026-05-18 · 97% similar
Identrust: Root CrossSign, of dedicated Roots, missing EKU
#1526099 RESOLVED Self Reported Incident Revocation Issue Audit Finding Opened 2019-02-07 · Closed 2023-02-22 · 96% similar
IdenTrust: Discrepancy in values of address fields within CN of SSL Certificates
#1542082 RESOLVED Incident Self Reported Incident Opened 2019-04-04 · Closed 2023-02-22 · 95% similar
IdenTrust: Failure to disclose Unconstrained intermediate Within 7 Days
#1756261 RESOLVED Certificate Misissuance Opened 2022-02-18 · Closed 2023-02-22 · 89% similar
IdenTrust: EV TLS certificate with invalid Jurisdiction state for government entity

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action