← IdenTrust Services, LLC cases
Bugzilla #1753287 Incident

IdenTrust: Validation Source for EV Certificates not Publicly Disclosed

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

IdenTrust Services, LLC discovered a compliance failure regarding the public disclosure of validation sources for Extended Validation (EV) certificates during an internal review. The CA identified that 943 EV TLS certificates were issued without the required disclosure, violating sections 11.1.3 and 9.2.4 of the CA/B Forum EV Guidelines. In response, IdenTrust disabled EV certificate issuance, publicly disclosed the vetting sources, and updated their policy documents. They communicated with affected subscribers to replace or revoke their certificates and are tracking the revocation process. The issue has been resolved with all affected certificates identified and remediation steps implemented.

Model: gpt-4o-mini Generated: 2026-06-13 21:16 UTC Revised: 2026-06-16 19:22 UTC Confidence: 0.90 11 comments
Chronology
  1. IdenTrust discovered non-compliance with EV Guidelines during an internal review.
  2. IdenTrust concluded the investigation and identified all mis-issued certificates.
  3. IdenTrust expected to complete the revocation of all affected certificates.
Thread Activity
  1. IdenTrust Services, LLC — IdenTrust reported non-compliance with EV Guidelines and initiated remediation.
  2. IdenTrust Services, LLC — IdenTrust provided a timeline of actions taken in response to the compliance failure.
  3. IdenTrust Services, LLC — IdenTrust acknowledged the need for improved internal reviews and compliance assessments.
  4. IdenTrust Services, LLC — IdenTrust confirmed that all pending activities related to the incident were completed.
Participants
IdenTrust Services, LLC Mozilla representative Community commenter
External References
Similar Local Cases
#1709192 RESOLVED Incident Opened 2021-05-03 · Closed 2023-02-22 · 100% similar
IdenTrust: Unavailable CRL for IdenTrust ‘DST Root CA X3’.
#1900492 RESOLVED Incident Opened 2024-06-03 · Closed 2026-06-10 · 97% similar
IdenTrust: Invalid OrganizationIdentifier in S/MIME certificates
#1905446 RESOLVED Incident Opened 2024-06-28 · Closed 2024-12-09 · 97% similar
IdenTrust: Unauthorized OCSP response on a Timestamp certificate
#1838315 RESOLVED Ca Security Vulnerability Incident Opened 2023-06-13 · Closed 2023-10-12 · 94% similar
IdenTrust: Certificate with missing details flagged by OCSP Watch
#2016585 RESOLVED Self Reported Incident Incident Opened 2026-02-12 · Closed 2026-06-15 · 90% similar
IdenTrust: Test Certificates from cross-signed roots not disclosed in CT Logs
#1542082 RESOLVED Incident Self Reported Incident Opened 2019-04-04 · Closed 2023-02-22 · 89% similar
IdenTrust: Failure to disclose Unconstrained intermediate Within 7 Days
#2014590 RESOLVED Self Reported Incident Incident Opened 2026-02-04 · Closed 2026-04-23 · 88% similar
IdenTrust: Unauthorized OCSP responses for cross-signed roots
#2014610 RESOLVED Self Reported Incident Incident Opened 2026-02-05 · Closed 2026-04-11 · 88% similar
IdenTrust: Root OCSP Signer certificate mis-issuance

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action