← IdenTrust Services, LLC cases
Bugzilla #1744627 Ca Certificate Compliance

IdenTrust: OV TLS certificate issued using account information verified more than 398 days earlier; certificate revoked and issuance controls deployed

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

IdenTrust staff discovered that an OV TLS certificate was requested and issued on 12/1/2021 for an organization whose account information had been verified more than 398 days earlier. On 12/3/2021, IdenTrust revoked the certificate after discovering the miss-issuance. IdenTrust also confirmed that remediation actions for incident report 1734917 would prevent further future mis-issuance once associated technical controls were propagated to production in January 2022. In further investigation, IdenTrust identified two additional organizations with account information verified prior to 398 days ago and inactivated those accounts to prevent further mis-issuance. IdenTrust explained that an interim report used to initiate re-verification did not list the problematic organization due to a design flaw in the report, which manifested for API-based requests for established organizations when the organization had no active certificates. IdenTrust stated that technical controls would reject OV TLS certificate issuance if account information was verified more than 398 days ago, with deployment dates described as January 2022 and later as effective 1/20/2022 across systems. The bug was marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:15 UTC Revised: 2026-06-16 19:19 UTC Confidence: 0.90 10 comments
Chronology
  1. An OV TLS certificate was requested and issued using account information verified more than 398 days earlier.
  2. IdenTrust discovered the miss-issuance and revoked the certificate; it also identified additional affected organizations and inactivated their accounts.
  3. IdenTrust deployed automated validation across systems to prevent recurrence.
Thread Activity
  1. IdenTrust Services, LLC — IdenTrust described how it discovered the issue during account information renewal verification, revoked the certificate, and outlined interim and future remediation including technical controls to reject issuance beyond the 398-day threshold.
  2. Community commenter — Ryan Sleevi requested substantive detail about the interim process and the reported “bug” in the supporting report.
  3. IdenTrust Services, LLC — IdenTrust explained the report design flaw and the conditions under which the organization was not listed for re-verification, leading to issuance before re-verification.
  4. Community commenter — Ryan Sleevi reiterated concerns about missing detail and asked for clarification of request paths and procedural controls.
  5. IdenTrust Services, LLC — IdenTrust clarified certificate request paths (website forms vs API) and stated the problematic certificate was received via an API path for an established organization; it also described how the report initiated re-verification.
  6. Mozilla representative — Ben Wilson suggested implementing controls with a safety margin (e.g., 395 days) to avoid edge cases.
  7. IdenTrust Services, LLC — IdenTrust responded that the report starts re-verification 45 days prior to the 398-day deadline and that automated validation stops issuance if the due date is over 397 days.
  8. IdenTrust Services, LLC — IdenTrust stated the technical controls would be deployed on January 22, 2022.
  9. IdenTrust Services, LLC — IdenTrust stated that effective 1/20/2022 it deployed automated validation across systems and that the issue was resolved.
  10. Mozilla representative — Ben Wilson indicated he would look at closing the bug next week if it could be closed.
Participants
IdenTrust Services, LLC Community commenter Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1598807 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-11-23 · Closed 2023-02-22 · 100% similar
IdenTrust: Undisclosed Unrevoked ICAs
#1749089 RESOLVED Ca Certificate Compliance Opened 2022-01-08 · Closed 2023-02-22 · 100% similar
IdenTrust: OCSP Signer Certificate Missing No-Check Extension
#1734917 RESOLVED Ca Certificate Compliance Opened 2021-10-08 · Closed 2023-02-22 · 98% similar
IdenTrust: Mis-Issued EV Certificates
#1883792 RESOLVED Ca Certificate Compliance Opened 2024-03-05 · Closed 2024-06-30 · 97% similar
IdenTrust: Temporary Errors in Test Website Certificates
#1853783 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2023-09-18 · Closed 2025-03-20 · 96% similar
IdenTrust: S/MIME certificates issued in violation of New S/MIME Baseline Requirements v1.0
#1861783 RESOLVED Ca Certificate Compliance Opened 2023-10-28 · Closed 2024-01-04 · 96% similar
IdenTrust: S/MIME Certificates issued without CAB Forum OID
#1772633 RESOLVED Ca Certificate Compliance Opened 2022-06-03 · Closed 2023-02-22 · 95% similar
IdenTrust: OCSP responses for subordinate CA exceed the validity period per CPS guidelines
#1876871 RESOLVED Ca Certificate Compliance Opened 2024-01-26 · Closed 2024-06-30 · 88% similar
IdenTrust: test certificates inadvertently published in production environment

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action