IdenTrust: Incorrect Subject Details for HydrantId
This case concerns a misissuance by IdenTrust of an EV SSL certificate for an internal end-entity (EV) certificate issued from an IdenTrust not-named-constrained ICA. On 04/28/2020, an EE EV SSL certificate was issued with incorrect subject details for the subscriber organization, and it was revoked the same day. During further investigation, IdenTrust found an additional EE OV SSL certificate issued from the same ICA that contained discrepancies in the certificate policy extension URIs compared to the CPS, and it was revoked on 05/05/2020. IdenTrust stated it halted issuance and rejected a pending application for a different EE EV SSL certificate for the same organization, and it confirmed there were no other active EV or OV certificates with the URI discrepancy. IdenTrust reported deploying a production change on 10/03/2020 and described a new back-office validation check that detects when an applicant organization name is a DBA name and triggers automated formatting to the expected “DBA Name (Parent Organization)” format. Mozilla indicated it would close the bug on or about 12-Oct-2020, and the bug is marked RESOLVED with resolution FIXED.
- IdenTrust issued an EE EV SSL certificate with incorrect subject details and revoked it the same day.
- IdenTrust discovered and revoked an EE OV SSL certificate with certificate policy extension URI values inconsistent with the CPS.
- IdenTrust deployed a production change to address the issue systemically.
- Community commenter — Reported that IdenTrust had disclosed a misissuance and linked to the certificate in crt.sh.
- IdenTrust Services, LLC — Acknowledged receipt and said they would investigate to reply.
- IdenTrust Services, LLC — Provided a formal incident description including issuance/revocation timeline, causes, and remediation steps.
- Mozilla representative — Noted a partial remediation code change scheduled for Q4/2020 and set the next update for 1-Oct-2020.
- IdenTrust Services, LLC — Stated that a production change addressing the issue was deployed on October 3, 2020.
- Mozilla representative — Asked for a short recap of what was deployed and said the bug would be closed on or about 12-Oct-2020 unless questions were raised.
- IdenTrust Services, LLC — Described the deployed remediation: a new back-office validation check for DBA names that triggers automated formatting to the expected subject format.
- Mozilla representative — Confirmed intent to close the bug on 12-Oct-2020.