IdenTrust: Inconsistent Disclosure of Externally-Operated Intermediate
IdenTrust disclosed an inconsistency regarding the operation of an intermediate certificate that was incorrectly flagged as being operated under its Certificate Policy/Certificate Practice Statement (CP/CPS). This issue was identified by a third party and led to IdenTrust acknowledging the error and correcting the entries in Mozilla's Common CA Database (CCADB). The CA committed to submitting a formal incident report detailing the timeline of events and corrective actions taken. The incident report was submitted by IdenTrust, outlining the steps they would take to prevent similar issues in the future, including enhanced internal controls for CCADB updates.
- IdenTrust became aware of the incorrect disclosure via a Bugzilla report.
- IdenTrust confirmed the error and began correcting the CCADB entries.
- IdenTrust acknowledged the requirement to supply a formal incident report.
- IdenTrust submitted the incident report detailing the issue and corrective actions.
- Mm representative — IdenTrust has disclosed an intermediate operated under the same CP/CPS as its parent, but it appears to be incorrectly disclosed.
- IdenTrust Services, LLC — We have corrected the entries in Mozilla's CCADB accordingly.
- Mozilla representative — I would like Identrust to prepare an incident report for this.
- IdenTrust Services, LLC — We acknowledge the requirement to supply a formal incident report.
- IdenTrust Services, LLC — IdenTrust submitted the incident report detailing the issue and corrective actions.