← IdenTrust Services, LLC cases
Bugzilla #1663080
Certificate Misissuance
IdenTrust: Issuance of certificates greater than 398 days
RESOLVED
FIXED
IdenTrust Services, LLC
AI Summary
IdenTrust identified and resolved an issue where two certificates were mis-issued with a validity period exceeding 398 days. This was discovered during an internal investigation prompted by discussions on ZLint GitHub regarding RFC 5280. The CA took immediate action, revoking one certificate and updating their configurations to limit future certificates to a maximum of 397 days. The incident highlighted a misunderstanding of the validity period definition in RFC 5280, which led to the mis-issuance.
Chronology
- Initiated internal investigation and revoked one mis-issued certificate.
- Completed investigation and began working on revocation/replacement of the second certificate.
- Updated configurations to set max validity period to 397 days.
Participants
IdenTrust
Ryan Sleevi
B Wilson
External References
Similar Local Cases
IdenTrust: Validation Source for EV Certificates not Publicly Disclosed
IdenTrust: Issuance of OV SSL Certificate with doc vetting older than 398 days
IdenTrust: Inconsistent Disclosure of Externally-Operated Intermediate
IdenTrust: Issuance of Subordinate CA’s Without EKU
IdenTrust: Mis-Issued EV Certificates
IdenTrust: Invalid special characters in S/MIME Certificates
IdenTrust: Improper encoding of wildcard certificate
IdenTrust: test certificates inadvertently published in production environment