IdenTrust: Validation Source for EV Certificates not Publicly Disclosed
IdenTrust Services, LLC discovered a compliance failure regarding the public disclosure of validation sources for Extended Validation (EV) certificates during an internal review. The CA identified that 943 EV TLS certificates were issued without the required disclosure, violating sections 11.1.3 and 9.2.4 of the CA/B Forum EV Guidelines. In response, IdenTrust disabled EV certificate issuance, publicly disclosed the vetting sources, and updated their policy documents. They communicated with affected subscribers to replace or revoke their certificates and are tracking the revocation process. The issue has been resolved with all affected certificates identified and remediation steps implemented.
- IdenTrust discovered non-compliance with EV Guidelines during an internal review.
- IdenTrust concluded the investigation and identified all mis-issued certificates.
- IdenTrust expected to complete the revocation of all affected certificates.
- IdenTrust Services, LLC — IdenTrust reported non-compliance with EV Guidelines and initiated remediation.
- IdenTrust Services, LLC — IdenTrust provided a timeline of actions taken in response to the compliance failure.
- IdenTrust Services, LLC — IdenTrust acknowledged the need for improved internal reviews and compliance assessments.
- IdenTrust Services, LLC — IdenTrust confirmed that all pending activities related to the incident were completed.