← IdenTrust Services, LLC cases
Bugzilla #1734906 Incident

IdenTrust: Intermitent interruptions to DNS service

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

IdenTrust reported an incident involving intermittent DNS service interruptions that it linked to the expiration of its IdenTrust Root DST X3 (DST X3) on September 30, 2021. IdenTrust system engineers were notified of large volumes of network traffic causing intermittent site connectivity, slow responses, and timeouts for customers attempting OCSP validations and other certificate lifecycle events. IdenTrust also logged intermittent CRL validation failures beginning around 5:00 pm MT on 10/05/2021 for traffic routed to a DR system via a round-robin method. IdenTrust determined the CRLs used by the DR system were not updated according to normal production protocol and were outdated, and after testing it pushed new CRLs to the DR system at 9:18 am MT on 10/06/2021, confirming resolution. In parallel, IdenTrust moved approximately 40% of traffic to its secondary site to alleviate bottlenecks and stabilize response times. IdenTrust stated that continued monitoring found no further DNS service interruptions and requested the bug be resolved as “Fixed,” with the bug status shown as RESOLVED and resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:14 UTC Revised: 2026-06-16 19:18 UTC Confidence: 0.90 3 comments
Chronology
  1. IdenTrust Root DST X3 (DST X3) expired as expected, triggering increased customer traffic to download the new certificate chain.
  2. Intermittent CRL validation failures were logged for traffic routed to the DR system via round-robin.
  3. IdenTrust identified outdated CRLs on the DR system and pushed updated CRLs to the DR system, confirming resolution.
Thread Activity
  1. IdenTrust Services, LLC — IdenTrust disclosed the incident, explaining how DST X3 expiration led to intermittent connectivity and CRL validation failures on the DR system, and provided a timeline of remediation actions including traffic redistribution and CRL updates.
  2. IdenTrust Services, LLC — IdenTrust reported continued monitoring with no further DNS service interruptions and stated no additional tasks were pending.
  3. IdenTrust Services, LLC — IdenTrust reported volumes had subsided with no further DNS service interruptions and requested the bug be resolved as “Fixed.”
Participants
IdenTrust Services, LLC
External References
Similar Local Cases
#1900492 RESOLVED Incident Opened 2024-06-03 · Closed 2026-06-10 · 87% similar
IdenTrust: Invalid OrganizationIdentifier in S/MIME certificates
#1905446 RESOLVED Incident Opened 2024-06-28 · Closed 2024-12-09 · 87% similar
IdenTrust: Unauthorized OCSP response on a Timestamp certificate
#2014590 RESOLVED Self Reported Incident Incident Opened 2026-02-04 · Closed 2026-04-23 · 86% similar
IdenTrust: Unauthorized OCSP responses for cross-signed roots
#2014610 RESOLVED Self Reported Incident Incident Opened 2026-02-05 · Closed 2026-04-11 · 86% similar
IdenTrust: Root OCSP Signer certificate mis-issuance
#2025595 RESOLVED Self Reported Incident Incident Opened 2026-03-23 · Closed 2026-05-18 · 86% similar
IdenTrust: Delay in updating a Bug 2014609 - Next update
#2025596 RESOLVED Self Reported Incident Incident Opened 2026-03-23 · Closed 2026-05-18 · 86% similar
IdenTrust: Delay in updating a Bugzilla ticket Bug 2014610 - Next update
#1542082 RESOLVED Incident Self Reported Incident Opened 2019-04-04 · Closed 2023-02-22 · 86% similar
IdenTrust: Failure to disclose Unconstrained intermediate Within 7 Days
#1709192 RESOLVED Incident Opened 2021-05-03 · Closed 2023-02-22 · 86% similar
IdenTrust: Unavailable CRL for IdenTrust ‘DST Root CA X3’.

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action