← LuxTrust cases
Bugzilla #1578505 Self Reported Incident

LuxTrust: Outdated audit statement for intermediate certificate

RESOLVED FIXED LuxTrust
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

LuxTrust reported that an intermediate certificate record in the CCADB had an outdated audit statement. The initial request asked LuxTrust to update the CCADB record with the current audit statement information and to provide an Incident Report for the overdue audit statement. LuxTrust said the issue was an omission in the attestation letter, and that it requested an updated attestation letter from the auditor on September 4, then updated the CCADB record after receiving it. LuxTrust also stated the incident was due to a wording oversight rather than an operational or security issue, and that it did not stop issuing certificates. In the thread, Mozilla noted that an incident report was not present as requested, and later checked whether LuxTrust had responded. Mozilla ultimately indicated the parent CA (LuxTrust Global Root 2) had been removed and closed the bug.

Model: gpt-5.4-nano Generated: 2026-06-13 19:34 UTC Revised: 2026-06-16 13:28 UTC Confidence: 0.86 10 comments
Chronology
  1. LuxTrust opened a CA Program bug requesting CCADB updates for an intermediate certificate with an outdated audit statement.
  2. LuxTrust reported requesting an updated attestation letter from the auditor and planned to update CCADB upon receipt.
  3. LuxTrust provided a link to the updated attestation letter and confirmed the CCADB record was updated and ALV passed.
  4. LuxTrust submitted an incident-report response describing the cause and remediation steps.
  5. Mozilla closed the bug after noting the parent CA had been removed.
Thread Activity
  1. Mozilla representative — Requested LuxTrust update the CCADB record for an intermediate certificate with an outdated audit statement and provide an Incident Report, citing the CCADB intermediate certificate page and Mozilla’s incident-report guidance URL.
  2. Luxtrust representative — Explained the outdated attestation was an omission in the attestation letter, said LuxTrust requested an updated attestation letter from the auditor on September 4, and would update CCADB upon receipt; stated a 4-eye verification process was put in place.
  3. Luxtrust representative — Provided a URL to the updated attestation letter PDF.
  4. Mozilla representative — Confirmed the audit attestation letter was added to CCADB and ALV passed, but asked to resolve additional intermediate-certificate audit-statement inconsistencies and to provide an Incident Report for those missing audit attestations.
  5. Community commenter — Stated there did not appear to be an incident report on the issue as requested.
  6. Luxtrust representative — Submitted a structured incident-report response describing how LuxTrust became aware, actions taken, that issuing was not stopped, the cause as a mistaken “Audits Same as Parent” tick and misunderstanding of requirements, and remediation steps including clarifying requirements and strengthening supervision of CCADB publication.
  7. Community commenter — Criticized the incident report for not addressing the significance of the CCADB publication gap and questioned whether calendar reminders would ensure continuity.
  8. Mozilla representative — Checked in, stating it appeared Mozilla was still awaiting a response from LuxTrust.
  9. Mozilla representative — Noted the parent CA (LuxTrust Global Root 2) had been removed and indicated inclination to close the bug.
  10. Mozilla representative — Closed the bug.
Participants
Mozilla representative Luxtrust representative Community commenter
Related Bugzilla IDs Mentioned
Similar Local Cases
#1575530 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-08-21 · Closed 2023-02-22 · 84% similar
Camerfirma: Govern d'Andorra audits
#1532559 RESOLVED Certificate Misissuance Self Reported Incident Opened 2019-03-05 · Closed 2023-02-22 · 81% similar
CFCA: Wrong SerialNumber encoding
#1549861 RESOLVED Repository Issue Self Reported Incident Opened 2019-05-07 · Closed 2023-02-22 · 77% similar
Camerfirma: Outdated audit statements for intermediate certs
#1675314 RESOLVED Self Reported Incident Opened 2020-11-04 · Closed 2023-02-22 · 76% similar
Telekom Security: Wrong jurisdiction entries in certificates
#1649963 RESOLVED Self Reported Incident Opened 2020-07-02 · Closed 2023-02-22 · 76% similar
Atos: Incorrect OCSP Delegated Responder Certificate
#1649951 RESOLVED Self Reported Incident Revocation Issue Opened 2020-07-02 · Closed 2023-02-22 · 76% similar
DigiCert: Incorrect OCSP Delegated Responder Certificate
#1599503 RESOLVED Self Reported Incident Opened 2019-11-26 · Closed 2024-06-30 · 76% similar
TrustCor: No mention of TLS-capable Intermediate CAs in WTBR audit reports
#1542302 RESOLVED Self Reported Incident Opened 2019-04-05 · Closed 2023-02-22 · 76% similar
E-Tugra: Insufficient serial number entropy

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action