← IdenTrust Services, LLC cases
Bugzilla #1677239 Self Reported Incident

IdenTrust: Service Degradation

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

IdenTrust reported a service degradation incident affecting its OCSP responder connectivity due to a DNS lookup failure. The CA said it first became aware of the problem on November 6, 2020 via an OCSP responder monitoring system alert, and later on November 7, 2020 after a customer reported an intermittent OCSP connection error. In its incident response, IdenTrust stated that one of its DNS servers became unstable due to a hardware controller error, and that the DNS server continued to respond with an empty value, causing some validation attempts to fail to reach the OCSP responder. IdenTrust said it temporarily removed the problematic DNS server from service and from the global registrar on November 7, 2020, and testing confirmed services were available afterward. The CA also reported post-incident actions including working with external vendors on virtual environment configuration changes and adjusting monitoring rules for greater granularity. In response to Mozilla’s question about detection and prevention, IdenTrust stated there was no issue with detection because internal and external monitoring performed as expected, and that the issue was an extreme edge case isolated to a specific load balancer; it also said the vendor provided changes to affect a more optimal failure mode. The bug was marked RESOLVED with resolution FIXED, and Mozilla indicated it could be closed around March 5, 2021.

Model: gpt-5.4-nano Generated: 2026-06-13 21:13 UTC Revised: 2026-06-16 19:17 UTC Confidence: 0.86 5 comments
Chronology
  1. IdenTrust’s OCSP responder monitoring system alerted to abnormal behavior that later related to a DNS lookup failure affecting OCSP connectivity.
  2. IdenTrust identified a DNS service degradation cause and temporarily removed the problematic DNS server from service and the global registrar to restore availability.
  3. Mozilla planned to close the bug around this date after review.
Thread Activity
  1. IdenTrust Services, LLC — IdenTrust provided an incident report describing a November 6–7, 2020 service degradation caused by unstable DNS behavior impacting OCSP validation traffic and outlined remediation steps and post-incident actions.
  2. Community commenter — Mozilla’s Ryan Sleevi asked for clearer explanation of how the issue avoided detection and what systemic mitigations were being put in place to improve detection and prevention.
  3. IdenTrust Services, LLC — IdenTrust replied that detection was not the issue, stating monitoring systems performed as expected, and described the edge-case scenario and subsequent monitoring rule granularity changes and vendor-provided failure-mode improvements.
  4. Mozilla representative — Mozilla stated the bug could be closed and planned to do so around March 5, 2021.
Participants
IdenTrust Services, LLC Community commenter Mozilla representative
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#1598807 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-11-23 · Closed 2023-02-22 · 92% similar
IdenTrust: Undisclosed Unrevoked ICAs
#1910195 RESOLVED Certificate Misissuance Self Reported Incident Opened 2024-07-26 · Closed 2024-09-06 · 85% similar
IdenTrust: Invalid special characters in S/MIME Certificates
#1933353 RESOLVED Self Reported Incident Opened 2024-11-25 · Closed 2025-03-21 · 85% similar
IdenTrust: Incorrect response for OCSP validation
#1794047 RESOLVED Revocation Issue Self Reported Incident Opened 2022-10-06 · Closed 2023-02-22 · 85% similar
IdenTrust: Missing Revocation Reasons in CRL
#1853783 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2023-09-18 · Closed 2025-03-20 · 84% similar
IdenTrust: S/MIME certificates issued in violation of New S/MIME Baseline Requirements v1.0
#1930029 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-11-08 · Closed 2025-02-19 · 84% similar
IdenTrust: Approval of TLS certificate renewal without domain validation
#2006483 RESOLVED Self Reported Incident Opened 2025-12-16 · Closed 2026-01-20 · 77% similar
IdenTrust: CT Logging Mistakes
#2025914 RESOLVED Self Reported Incident Audit Delay Opened 2026-03-24 · Closed 2026-05-18 · 77% similar
IdenTrust: Full Incident Report for bug 2014610 was not published within 14 days of discovering the issue

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action