IdenTrust: Issuance of certificates greater than 398 days
IdenTrust Services, LLC identified a compliance issue regarding the issuance of SSL/TLS certificates with a validity period exceeding 398 days. This was discovered following discussions on the ZLint GitHub repository, prompting an internal investigation. IdenTrust found two mis-issued certificates, one of which was revoked immediately, while the second was in the process of being revoked. The CA updated its configurations to limit the maximum validity period to 397 days. The issue arose from a misunderstanding of the inclusive definition of validity periods in RFC 5280. IdenTrust has since implemented changes to ensure compliance and prevent future occurrences.
- IdenTrust initiated an internal investigation after discovering mis-issued certificates.
- IdenTrust revoked one certificate and updated configurations to limit validity to 397 days.
- IdenTrust Services, LLC — IdenTrust disclosed the discovery of mis-issued certificates exceeding 398 days.
- IdenTrust Services, LLC — IdenTrust confirmed the revocation of one of the mis-issued certificates.
- Community commenter — Inquired about the review process related to CA/B Forum compliance.
- IdenTrust Services, LLC — IdenTrust updated their compliance monitoring process to include risk assessment.
- Mozilla representative — Indicated intent to close the case.