TrustCor: Non-audited intermediate certificates
This case concerns TrustCor intermediate certificates that were not audited but still chain up to Mozilla-trusted root certificates. The issue was identified after the reporter learned from Mozilla disclosure-related CRT.sh pages that TrustCor had non-revoked, superseded intermediate certificates that were not audited, yet remained technically trusted by Firefox via included root certificates. The thread states that TrustCor regenerated their root certificates per a referenced bug, and that the older intermediates were created under superseded roots. TrustCor’s Policy Authority agreed that revoking the listed certificates was the best path rather than including the superseded certificates in the audit scope. TrustCor revoked the listed certificates effective 2019-09-13 and updated its CRL and OCSP services accordingly, and asked that the certificates be added to OneCRL. The CA also instructed updating CCADB to indicate the revocation status, and later confirmed that the certificates were revoked and CCADB was updated. The bug is resolved as FIXED.
- TrustCor case opened regarding non-audited intermediate certificates that chain to Mozilla-trusted roots.
- TrustCor revoked the listed intermediate certificates and updated CRL/OCSP services.
- CCADB revocation status update was completed per TrustCor instructions.
- Reporter confirmed revocation and CCADB updates; case marked resolved.
- Community commenter — Reported that TrustCor has non-revoked, superseded intermediate certificates that are not audited but chain to Mozilla-trusted roots, and listed specific roots/intermediates that need revocation or audit-scope inclusion.
- Community commenter — Stated TrustCor’s Policy Authority agreed to revoke the listed certificates (effective 2019-09-13), updated CRL/OCSP, and provided the revoked certificate details.
- Community commenter — Requested that CCADB be updated to mark the intermediates as revoked, linking to the CCADB instructions.
- Community commenter — Confirmed CCADB was updated per the instructions.
- Community commenter — Confirmed the certificates are revoked and CCADB reflects their revocation status.