← IdenTrust Services, LLC cases
Bugzilla #1671410 Self Reported Incident

IdenTrust: Inconsistent Disclosure of Externally-Operated Intermediate

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

IdenTrust disclosed an inconsistency regarding the operation of an intermediate certificate that was incorrectly flagged as being operated under its Certificate Policy/Certificate Practice Statement (CP/CPS). This issue was identified by a third party and led to IdenTrust acknowledging the error and correcting the entries in Mozilla's Common CA Database (CCADB). The CA committed to submitting a formal incident report detailing the timeline of events and corrective actions taken. The incident report was submitted by IdenTrust, outlining the steps they would take to prevent similar issues in the future, including enhanced internal controls for CCADB updates.

Model: gpt-4o-mini Generated: 2026-06-13 21:13 UTC Revised: 2026-06-16 19:17 UTC Confidence: 0.85 19 comments
Chronology
  1. IdenTrust became aware of the incorrect disclosure via a Bugzilla report.
  2. IdenTrust confirmed the error and began correcting the CCADB entries.
  3. IdenTrust acknowledged the requirement to supply a formal incident report.
  4. IdenTrust submitted the incident report detailing the issue and corrective actions.
Thread Activity
  1. Mm representative — IdenTrust has disclosed an intermediate operated under the same CP/CPS as its parent, but it appears to be incorrectly disclosed.
  2. IdenTrust Services, LLC — We have corrected the entries in Mozilla's CCADB accordingly.
  3. Mozilla representative — I would like Identrust to prepare an incident report for this.
  4. IdenTrust Services, LLC — We acknowledge the requirement to supply a formal incident report.
  5. IdenTrust Services, LLC — IdenTrust submitted the incident report detailing the issue and corrective actions.
Participants
Community commenter
External References
Similar Local Cases
#2016267 RESOLVED Self Reported Incident Incident Opened 2026-02-11 · Closed 2026-04-17 · 87% similar
IdenTrust: Gap between audit periods
#2014590 RESOLVED Self Reported Incident Incident Opened 2026-02-04 · Closed 2026-04-23 · 84% similar
IdenTrust: Unauthorized OCSP responses for cross-signed roots
#2016585 RESOLVED Self Reported Incident Incident Opened 2026-02-12 · Closed 2026-06-15 · 82% similar
IdenTrust: Test Certificates from cross-signed roots not disclosed in CT Logs
#1446121 RESOLVED Self Reported Incident Security Incident Opened 2018-03-15 · Closed 2023-02-22 · 82% similar
IdenTrust: Improper encoding of wildcard certificate
#1930029 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-11-08 · Closed 2025-02-19 · 81% similar
IdenTrust: Approval of TLS certificate renewal without domain validation
#2014609 RESOLVED Self Reported Incident Certificate Misissuance Opened 2026-02-05 · Closed 2026-04-11 · 81% similar
IdenTrust: Cross-signed root certificate mis-issuance
#2014610 RESOLVED Self Reported Incident Incident Opened 2026-02-05 · Closed 2026-04-11 · 81% similar
IdenTrust: Root OCSP Signer certificate mis-issuance
#1910195 RESOLVED Certificate Misissuance Self Reported Incident Opened 2024-07-26 · Closed 2024-09-06 · 80% similar
IdenTrust: Invalid special characters in S/MIME Certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action