← IdenTrust Services, LLC cases
Bugzilla #1669594 Certificate Misissuance

IdenTrust: Issuance of Subordinate CA’s Without EKU

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

IdenTrust reported that, during a final review before production deployment, it discovered that two subordinate CA certificates issued from its DST Root CA X3 on September 30, 2020 were missing the required EKU extension required by BR 1.7.2, section 7.1.2.2g. IdenTrust stated it had stopped issuing certificates from those two subordinate CA certificates and that zero production end-entity certificates were issued from them. The CA obtained approval to revoke/re-issue, created new subordinate certificates including the EKU extension, and revoked the two mis-issued subordinate CA certificates. IdenTrust also updated Mozilla’s CCADB records accordingly. In the thread, Mozilla asked for more specificity about procedural controls, and IdenTrust provided details of its compliance validation controls and how they were tightened for new, renewed, or replaced subordinate CA certificates. Mozilla indicated no further questions and stated the matter could be closed on 27-Jan-2021 unless additional comments were raised. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:12 UTC Revised: 2026-06-16 19:16 UTC Confidence: 0.86 10 comments
Chronology
  1. IdenTrust issued two subordinate CA certificates from DST Root CA X3 that were missing the required EKU extension.
  2. IdenTrust discovered the missing EKU issue during a final review before production deployment.
  3. IdenTrust created new subordinate CA certificates including the EKU extension and revoked the two mis-issued subordinate CA certificates.
  4. IdenTrust added the incident report to the bug.
  5. Mozilla planned to close the matter unless there were additional comments or areas to explore.
Thread Activity
  1. IdenTrust Services, LLC — IdenTrust stated it discovered two subordinate CAs issued from DST Root CA X3 were missing required EKU extensions and said remediation was being planned and executed, with an incident report to follow.
  2. Mm representative — A third party asked whether the referenced intermediate certificate lacking EKU was one of the two certificates mentioned and questioned why an incident report had not yet been provided.
  3. IdenTrust Services, LLC — IdenTrust confirmed the certificate was one of the two and provided the other crt.sh reference, stating an incident report would be supplied by October 16, 2016.
  4. IdenTrust Services, LLC — IdenTrust provided the incident report details, including how it became aware, a timeline, that issuance was stopped, revocation actions, and an explanation of how the mistakes occurred.
  5. Community commenter — Mozilla asked for more specificity about procedural controls and requested detailed information about existing and current controls.
  6. IdenTrust Services, LLC — IdenTrust described its compliance validation controls and noted updates to make profile review stricter for new, renewed, or replaced subordinate CAs.
  7. Mozilla representative — Mozilla stated it had no other questions at that time.
  8. Mozilla representative — Mozilla suggested wording changes related to CCADB updates and noted a side note about notice-and-approval for new external CA operators.
  9. IdenTrust Services, LLC — IdenTrust agreed and stated its process includes a second pair of eyes reviewing CCADB updates via a screen-sharing session.
  10. Mozilla representative — Mozilla said the matter could be closed next Wednesday (27-Jan-2021) unless there were other comments or areas to explore.
Participants
IdenTrust Services, LLC Mm representative Community commenter Mozilla representative
Similar Local Cases
#1850807 RESOLVED Certificate Misissuance Opened 2023-08-30 · Closed 2023-09-29 · 100% similar
IdenTrust: basicConstraints not flagged "Critical" Per Certification Practices Statement
#1635279 RESOLVED Certificate Misissuance Opened 2020-05-04 · Closed 2023-02-22 · 100% similar
IdenTrust: Incorrect Subject Details for HydrantId
#1796715 RESOLVED Certificate Misissuance Opened 2022-10-20 · Closed 2023-02-22 · 97% similar
IdenTrust: Mis-Issued EV Code Signing Certificate
#1897569 RESOLVED Certificate Misissuance Opened 2024-05-17 · Closed 2024-08-23 · 96% similar
IdenTrust: TLS ICA with User Notice in Policy Qualifier
#1861782 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-10-28 · Closed 2024-01-04 · 95% similar
IdenTrust: S/MIME certificates with Invalid document Identification Scheme
#1919162 RESOLVED Certificate Misissuance Opened 2024-09-16 · Closed 2024-12-09 · 87% similar
IdenTrust: TLS Certificates with outdated certificate profile
#1670337 RESOLVED Certificate Misissuance Opened 2020-10-09 · Closed 2024-01-16 · 84% similar
Microsoft PKI Services: Certificate Mis-Issuance, DNSNames must have a valid TLD
#1663080 RESOLVED Certificate Misissuance Opened 2020-09-03 · Closed 2023-02-22 · 83% similar
IdenTrust: Issuance of certificates greater than 398 days

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action