IdenTrust audit report omissions for intermediate CA thumbprints and related disclosures
This case concerns missing SHA-256 thumbprints and related disclosure issues for several IdenTrust intermediate CA certificates in annual WebTrust audit reports and the CCADB. IdenTrust opened the bug after noticing 14 intermediate records flagged with failed ALV results in CCADB, and initially said there were no misissued certificates or security issues. Mozilla reviewers asked for clearer identification of the affected certificates and noted that some items appeared to require revocation or corrected audit reporting rather than waiting for the next audit cycle. IdenTrust later acknowledged that some certificates were missing from the BR report, that one certificate had been mischaracterized as not capable of TLS issuance, and that corrected reports were needed. The company then produced updated audit reports, submitted a separate incident report in Bug 1598807 for the revocation-related items, and Mozilla later concluded that the remaining audit-report issues were covered and that this bug could be closed as fixed.
- IdenTrust discovered 14 intermediate CA records flagged with failed ALV results in CCADB.
- IdenTrust said the missing thumbprints were a reporting oversight and that some items were not in scope of the supplied audit reports.
- IdenTrust filed a formal incident report and said updated audit reports had been received.
- IdenTrust revoked five doppelganger intermediate CA certificates.
- Mozilla reviewed the updated reports and said the remaining issues were covered, with no other issues remaining in this bug.
- IdenTrust Services, LLC — IdenTrust reported 14 intermediate certs with failed ALV results and said it would provide a formal incident report by October 18, 2019.
- IdenTrust Services, LLC — IdenTrust listed the 14 flagged subordinate CA certificates and explained which ones were covered by audit reports, AUP letters, or were doppelgangers.
- Fastly representative — Wayne Thayer asked for clearer identification of the certificates and said unresolved items needed revocation, OneCRL, or a corrected report.
- IdenTrust Services, LLC — IdenTrust said it was working with auditors to correct the reports and provide a corrected version.
- Community commenter — Ryan Sleevi said waiting for the next audit cycle would not address the assurance problem and urged broader disclosure and remediation.
- IdenTrust Services, LLC — IdenTrust said it expected to supply updated audit reports by November 5, 2019.
- IdenTrust Services, LLC — IdenTrust submitted a formal incident report describing how it learned of the issue, the timeline, and planned revocation of five ICA certificates.
- IdenTrust Services, LLC — IdenTrust attached updated 2019 WebTrust audit reports and said it would submit a new CCADB audit case once the seals were updated.
- IdenTrust Services, LLC — IdenTrust said the new reports were verified in CCADB via case 510 and that relevant root stores were notified.
- IdenTrust Services, LLC — IdenTrust said CA A7 and CA A8 had AUP letters and that five doppelganger ICAs had been revoked that day.
- Mozilla representative — Ben Wilson said the attached audit reports covered the discussed CAs and that Bug 1598807 adequately covered CA A7 and CA A8.