← IdenTrust Services, LLC cases
Bugzilla #1598807
Ca Certificate Compliance
Self Reported Incident
IdenTrust: Undisclosed Unrevoked ICAs
RESOLVED
FIXED
IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
IdenTrust Services, LLC disclosed a compliance issue regarding two unrevoked intermediate certificates (ICAs) that were not disclosed in their annual WebTrust audit report. The CA became aware of the issue on November 8, 2019, through feedback related to a previous bug. Following this, IdenTrust agreed to place the ICAs on OneCRL and initiated a revocation process. By August 30, 2020, IdenTrust completed the revocation of the two ICAs and established a private infrastructure with new ICAs subordinated under a Private Root CA. The case has been resolved with all planned actions completed.
Chronology
- IdenTrust became aware of the need to revoke two ICAs due to lack of disclosure.
- IdenTrust completed the revocation of the two ICAs.
Thread Activity
- IdenTrust Services, LLC — IdenTrust provided details on how they became aware of the problem and the actions taken.
- IdenTrust Services, LLC — IdenTrust confirmed that all items of their remediation plan were completed.
- Mozilla representative — Ben Wilson indicated intent to close the bug unless there were objections.
Participants
IdenTrust Services, LLC
Mozilla representative
Community commenter
Tree representative
External References
Similar Local Cases
IdenTrust: S/MIME certificates issued in violation of New S/MIME Baseline Requirements v1.0
IdenTrust: Issuance of OV SSL Certificate with doc vetting older than 398 days
IdenTrust: OCSP Signer Certificate Missing No-Check Extension
IdenTrust: Mis-Issued EV Certificates
IdenTrust: Incorrect response for OCSP validation
IdenTrust: S/MIME Certificates issued without CAB Forum OID
IdenTrust: Temporary Errors in Test Website Certificates
IdenTrust: Invalid special characters in S/MIME Certificates