← IdenTrust Services, LLC cases
Bugzilla #1749089 Ca Certificate Compliance

IdenTrust: OCSP Signer Certificate Missing No-Check Extension

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

IdenTrust Services, LLC discovered a compliance issue during an internal audit on December 29, 2021, where an OCSP Responder certificate issued for the 'HydrantID Server CA O1' was missing the required 'id-pkix-ocsp-nocheck' extension. Following the discovery, IdenTrust confirmed the mis-issuance, revoked the problematic certificate, and implemented corrective measures, including updating their issuance script and conducting post-issuance quality checks. The issue was resolved by August 31, 2022, with the updated utility ensuring compliance for future certificates. The case was marked as resolved on February 22, 2023.

Model: gpt-4o-mini Generated: 2026-06-13 21:15 UTC Revised: 2026-06-16 19:22 UTC Confidence: 0.90 17 comments
Chronology
  1. Internal audit discovered a missing extension in an OCSP Responder certificate.
  2. The mis-issued certificate was revoked.
  3. The issuance utility was updated to prevent future issues.
Thread Activity
  1. IdenTrust Services, LLC — Created a bug report detailing the discovery of the missing extension.
  2. IdenTrust Services, LLC — Confirmed they are on track with the remediation steps.
  3. Community commenter — Questioned the transparency of the remediation priorities.
  4. IdenTrust Services, LLC — Announced the update of the issuance utility to ensure compliance.
  5. Mozilla representative — Indicated intention to close the case.
Participants
IdenTrust Services, LLC Mozilla representative Community commenter
External References
Similar Local Cases
#1598807 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-11-23 · Closed 2023-02-22 · 100% similar
IdenTrust: Undisclosed Unrevoked ICAs
#1744627 RESOLVED Ca Certificate Compliance Opened 2021-12-06 · Closed 2023-02-22 · 100% similar
IdenTrust: Issuance of OV SSL Certificate with doc vetting older than 398 days
#1734917 RESOLVED Ca Certificate Compliance Opened 2021-10-08 · Closed 2023-02-22 · 99% similar
IdenTrust: Mis-Issued EV Certificates
#1853783 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2023-09-18 · Closed 2025-03-20 · 96% similar
IdenTrust: S/MIME certificates issued in violation of New S/MIME Baseline Requirements v1.0
#1861783 RESOLVED Ca Certificate Compliance Opened 2023-10-28 · Closed 2024-01-04 · 96% similar
IdenTrust: S/MIME Certificates issued without CAB Forum OID
#1883792 RESOLVED Ca Certificate Compliance Opened 2024-03-05 · Closed 2024-06-30 · 96% similar
IdenTrust: Temporary Errors in Test Website Certificates
#1772633 RESOLVED Ca Certificate Compliance Opened 2022-06-03 · Closed 2023-02-22 · 96% similar
IdenTrust: OCSP responses for subordinate CA exceed the validity period per CPS guidelines
#1876871 RESOLVED Ca Certificate Compliance Opened 2024-01-26 · Closed 2024-06-30 · 84% similar
IdenTrust: test certificates inadvertently published in production environment

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action