← TrustCor Systems cases
Bugzilla #1579284
Certificate Problem Report
TrustCor: Non-audited intermediate certificates
RESOLVED
FIXED
TrustCor Systems
AI Summary
TrustCor Systems identified non-audited intermediate certificates that were still trusted despite being superseded. Following discussions, TrustCor agreed to revoke these certificates rather than include them in their audit scope. The revocation was executed on September 13, 2019, and the necessary updates were made to their CRL and OCSP services. The revocation status has been confirmed and updated in the CCADB.
Chronology
- Initial report of non-audited intermediate certificates
- Certificates revoked and CRL/OCSP updated
- Confirmation of revocation status update in CCADB
Participants
Kathleen Wilson
Neil Dunbar
External References
Similar Local Cases
TrustCor: No mention of TLS-capable Intermediate CAs in WTBR audit reports
TrustCor: Non-revocation of CA certificates within 7 days
TrustCor: Insufficient Serial Number Entropy
Dhimyotis / Certigna: Intermediate CAs missing audits
Firmaprofesional / SIGNE: No BR Audit for intermediate CA technically capable of issuing TLS certs
Add DigiCert non-TLS Intermediate Certs to OneCRL
Add Consorci AOC "old" hierarchy to OneCRL
DigiCert: Revoked intermediate certificates not in CRL