← IdenTrust Services, LLC cases
Bugzilla #1718552 Certificate Misissuance

IdenTrust: Certificates with Invalid values for stateOrProvinceName

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

IdenTrust Services, LLC reported a compliance issue involving several of their OV SSL certificates that contained invalid values in the 'stateOrProvinceName' field. The issue was first identified on June 28, 2021, following a report from Entrust. In response, IdenTrust confirmed the problem, revoked 40 affected certificates by June 30, 2021, and deployed a code fix to prevent recurrence. The root cause was identified as a software bug introduced in February 2019, which allowed 'Not Applicable' to be erroneously included in the certificates. IdenTrust has since implemented additional testing measures to avoid similar issues in the future.

Model: gpt-4o-mini Generated: 2026-06-13 21:14 UTC Revised: 2026-06-16 19:18 UTC Confidence: 0.85 12 comments
Chronology
  1. IdenTrust received a report about invalid values in the 'stateOrProvinceName' field of several SSL certificates.
  2. IdenTrust revoked 40 affected SSL certificates.
  3. IdenTrust provided a formal incident report detailing the issue and corrective actions.
  4. IdenTrust implemented a code update to prevent future occurrences of the issue.
Thread Activity
  1. IdenTrust Services, LLC — IdenTrust acknowledged the issue and stated they would provide a formal incident report by July 2, 2021.
  2. IdenTrust Services, LLC — IdenTrust confirmed the issue and scheduled the revocation of affected certificates.
  3. IdenTrust Services, LLC — IdenTrust submitted a detailed incident report outlining the timeline and corrective actions taken.
  4. Community commenter — Feedback was provided regarding the incident report's lack of clarity on root causes.
  5. IdenTrust Services, LLC — IdenTrust requested consideration for closing the report after addressing feedback.
Participants
IdenTrust Services, LLC Community commenter Mozilla representative
External References
Similar Local Cases
#1663080 RESOLVED Certificate Misissuance Opened 2020-09-03 · Closed 2023-02-22 · 100% similar
IdenTrust: Issuance of certificates greater than 398 days
#1895006 RESOLVED Certificate Misissuance Opened 2024-05-03 · Closed 2024-08-23 · 97% similar
IdenTrust: unintended creation of a Root CA certificate
#1910195 RESOLVED Certificate Misissuance Self Reported Incident Opened 2024-07-26 · Closed 2024-09-06 · 97% similar
IdenTrust: Invalid special characters in S/MIME Certificates
#1930029 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-11-08 · Closed 2025-02-19 · 97% similar
IdenTrust: Approval of TLS certificate renewal without domain validation
#1756261 RESOLVED Certificate Misissuance Opened 2022-02-18 · Closed 2023-02-22 · 95% similar
IdenTrust: EV TLS certificate with invalid Jurisdiction state for government entity
#1756850 RESOLVED Certificate Misissuance Opened 2022-02-23 · Closed 2023-02-22 · 95% similar
IdenTrust: EV TLS certificate with wrong jurisdiction state for private organization
#1831004 RESOLVED Certificate Misissuance Opened 2023-05-02 · Closed 2024-05-09 · 95% similar
IdenTrust: duplicate Certificate in error flagged by OCSP Watch
#1853783 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2023-09-18 · Closed 2025-03-20 · 94% similar
IdenTrust: S/MIME certificates issued in violation of New S/MIME Baseline Requirements v1.0

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action