IdenTrust: OV TLS certificate issued using account information verified more than 398 days earlier; certificate revoked and issuance controls deployed
IdenTrust staff discovered that an OV TLS certificate was requested and issued on 12/1/2021 for an organization whose account information had been verified more than 398 days earlier. On 12/3/2021, IdenTrust revoked the certificate after discovering the miss-issuance. IdenTrust also confirmed that remediation actions for incident report 1734917 would prevent further future mis-issuance once associated technical controls were propagated to production in January 2022. In further investigation, IdenTrust identified two additional organizations with account information verified prior to 398 days ago and inactivated those accounts to prevent further mis-issuance. IdenTrust explained that an interim report used to initiate re-verification did not list the problematic organization due to a design flaw in the report, which manifested for API-based requests for established organizations when the organization had no active certificates. IdenTrust stated that technical controls would reject OV TLS certificate issuance if account information was verified more than 398 days ago, with deployment dates described as January 2022 and later as effective 1/20/2022 across systems. The bug was marked RESOLVED with resolution FIXED.
- An OV TLS certificate was requested and issued using account information verified more than 398 days earlier.
- IdenTrust discovered the miss-issuance and revoked the certificate; it also identified additional affected organizations and inactivated their accounts.
- IdenTrust deployed automated validation across systems to prevent recurrence.
- IdenTrust Services, LLC — IdenTrust described how it discovered the issue during account information renewal verification, revoked the certificate, and outlined interim and future remediation including technical controls to reject issuance beyond the 398-day threshold.
- Community commenter — Ryan Sleevi requested substantive detail about the interim process and the reported “bug” in the supporting report.
- IdenTrust Services, LLC — IdenTrust explained the report design flaw and the conditions under which the organization was not listed for re-verification, leading to issuance before re-verification.
- Community commenter — Ryan Sleevi reiterated concerns about missing detail and asked for clarification of request paths and procedural controls.
- IdenTrust Services, LLC — IdenTrust clarified certificate request paths (website forms vs API) and stated the problematic certificate was received via an API path for an established organization; it also described how the report initiated re-verification.
- Mozilla representative — Ben Wilson suggested implementing controls with a safety margin (e.g., 395 days) to avoid edge cases.
- IdenTrust Services, LLC — IdenTrust responded that the report starts re-verification 45 days prior to the 398-day deadline and that automated validation stops issuance if the due date is over 397 days.
- IdenTrust Services, LLC — IdenTrust stated the technical controls would be deployed on January 22, 2022.
- IdenTrust Services, LLC — IdenTrust stated that effective 1/20/2022 it deployed automated validation across systems and that the issue was resolved.
- Mozilla representative — Ben Wilson indicated he would look at closing the bug next week if it could be closed.