← TrustCor Systems cases
Bugzilla #1599503 Self Reported Incident

TrustCor: No mention of TLS-capable Intermediate CAs in WTBR audit reports

RESOLVED FIXED TrustCor Systems
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

TrustCor reported that Mozilla alerted it to discrepancies between its WebTrust for CAs report and its SSL Baseline with Network Security report for two subordinate CAs. TrustCor stated that it had failed to disclose the subordinate CAs in both reports, which it recognized as a violation of BR Section 8.1, and said the omission was due to a misreading of requirements for CA certificates not intended for SSL certificate issuance (S/MIME in this case). TrustCor described actions including investigating the scope, communicating with its independent auditor, suspending its Enhanced Secure Email CA program temporarily, reconciling HSM activities with issuance logs, reorganizing CCADB data to remove mistaken certificates from the ALV report, and submitting new audit reports that mentioned the Email CAs in the SSL-BR report. TrustCor also stated that it requested addition of the Email CA certificates to OneCRL. In follow-up, TrustCor reported that the Basic Secure Email CA certificate was revoked (as of 2020-04-01 17:05:00 UTC) and that the Enhanced Secure Email CA certificate was formally revoked (as of 2019-12-05 17:10:18 UTC), and that new CRLs and OCSP responses were published. The thread indicates remediation was complete and the bug was resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 20:19 UTC Revised: 2026-06-16 18:13 UTC Confidence: 0.86 6 comments
Chronology
  1. Mozilla Dev Security Policy post alerted TrustCor to discrepancies between its basic audit report and SSL-BR audit report.
  2. TrustCor formally suspended its Enhanced Secure Email CA program pending resolution.
  3. TrustCor completed a self-audit and submitted new audit reports that mentioned the Email CAs in the SSL-BR report.
  4. TrustCor formally revoked the Enhanced Secure Email CA certificate.
  5. TrustCor revoked the Basic Secure Email CA certificate and published new CRLs and OCSP responses.
Thread Activity
  1. Trustcorsystems representative — Opened the case describing how TrustCor became aware of the reporting discrepancy, the cause (misreading requirements), and the remediation steps including new audit reports and OneCRL addition request.
  2. Trustcorsystems representative — Provided crt.sh links for the two CA certificates and clarified that no SSL certificates were logged under them via CT logs.
  3. Mozilla representative — Updated CCADB records to mark the corresponding intermediates as "Ready to Add" to OneCRL and shared the CCADB URL.
  4. Trustcorsystems representative — Reported revocation of the Basic Secure Email CA (2020-04-01 17:05:00 UTC) and that the Enhanced Secure Email CA had been formally revoked on 2019-12-05 17:10:18 UTC, with new CRLs/OCSP published.
  5. Community commenter — Noted that Bug 1599571 tracks delayed revocation and suggested the case be ready for closure if agreed.
  6. Fastly representative — Confirmed it appeared all questions were answered and remediation was complete.
Participants
Trustcorsystems representative Mozilla representative Community commenter Fastly representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1568356 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-07-23 · Closed 2023-02-22 · 95% similar
TrustCor: Incorrect CA-Issuers URI
#1575530 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-08-21 · Closed 2023-02-22 · 85% similar
Camerfirma: Govern d'Andorra audits
#1391056 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-08-16 · Closed 2023-02-22 · 83% similar
NetLock: Non-BR-Compliant Certificate Issuance
#1391064 RESOLVED Self Reported Incident Incident Closure Request Opened 2017-08-16 · Closed 2023-02-22 · 82% similar
SECOM: Non-BR-Compliant Certificate Issuance
#1542302 RESOLVED Self Reported Incident Opened 2019-04-05 · Closed 2023-02-22 · 82% similar
E-Tugra: Insufficient serial number entropy
#1532559 RESOLVED Certificate Misissuance Self Reported Incident Opened 2019-03-05 · Closed 2023-02-22 · 82% similar
CFCA: Wrong SerialNumber encoding
#1549861 RESOLVED Repository Issue Self Reported Incident Opened 2019-05-07 · Closed 2023-02-22 · 82% similar
Camerfirma: Outdated audit statements for intermediate certs
#1397969 RESOLVED Self Reported Incident Opened 2017-09-08 · Closed 2023-02-22 · 81% similar
DigiCert / Inteso San Paulo: Double dot characters

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action