← IdenTrust Services, LLC cases
Bugzilla #1663080 Certificate Misissuance

IdenTrust: Issuance of certificates greater than 398 days

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

IdenTrust Services, LLC identified a compliance issue regarding the issuance of SSL/TLS certificates with a validity period exceeding 398 days. This was discovered following discussions on the ZLint GitHub repository, prompting an internal investigation. IdenTrust found two mis-issued certificates, one of which was revoked immediately, while the second was in the process of being revoked. The CA updated its configurations to limit the maximum validity period to 397 days. The issue arose from a misunderstanding of the inclusive definition of validity periods in RFC 5280. IdenTrust has since implemented changes to ensure compliance and prevent future occurrences.

Model: gpt-4o-mini Generated: 2026-06-13 21:12 UTC Revised: 2026-06-16 19:16 UTC Confidence: 0.85 11 comments
Chronology
  1. IdenTrust initiated an internal investigation after discovering mis-issued certificates.
  2. IdenTrust revoked one certificate and updated configurations to limit validity to 397 days.
Thread Activity
  1. IdenTrust Services, LLC — IdenTrust disclosed the discovery of mis-issued certificates exceeding 398 days.
  2. IdenTrust Services, LLC — IdenTrust confirmed the revocation of one of the mis-issued certificates.
  3. Community commenter — Inquired about the review process related to CA/B Forum compliance.
  4. IdenTrust Services, LLC — IdenTrust updated their compliance monitoring process to include risk assessment.
  5. Mozilla representative — Indicated intent to close the case.
Participants
IdenTrust Services, LLC Community commenter Mozilla representative
External References
Similar Local Cases
#1718552 RESOLVED Certificate Misissuance Opened 2021-06-28 · Closed 2023-02-22 · 100% similar
IdenTrust: Certificates with Invalid values for stateOrProvinceName
#1930029 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-11-08 · Closed 2025-02-19 · 96% similar
IdenTrust: Approval of TLS certificate renewal without domain validation
#1756850 RESOLVED Certificate Misissuance Opened 2022-02-23 · Closed 2023-02-22 · 96% similar
IdenTrust: EV TLS certificate with wrong jurisdiction state for private organization
#1853783 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2023-09-18 · Closed 2025-03-20 · 95% similar
IdenTrust: S/MIME certificates issued in violation of New S/MIME Baseline Requirements v1.0
#1910195 RESOLVED Certificate Misissuance Self Reported Incident Opened 2024-07-26 · Closed 2024-09-06 · 95% similar
IdenTrust: Invalid special characters in S/MIME Certificates
#1756261 RESOLVED Certificate Misissuance Opened 2022-02-18 · Closed 2023-02-22 · 95% similar
IdenTrust: EV TLS certificate with invalid Jurisdiction state for government entity
#1895006 RESOLVED Certificate Misissuance Opened 2024-05-03 · Closed 2024-08-23 · 94% similar
IdenTrust: unintended creation of a Root CA certificate
#1831004 RESOLVED Certificate Misissuance Opened 2023-05-02 · Closed 2024-05-09 · 94% similar
IdenTrust: duplicate Certificate in error flagged by OCSP Watch

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action