← IdenTrust Services, LLC cases
Bugzilla #1756850 Certificate Misissuance

IdenTrust: EV TLS test certificate issued with wrong jurisdiction state for private organization (resolved)

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

IdenTrust Services, LLC reported a compliance discrepancy it discovered during an internal review of CAB Forum compliance. The CA stated that, as part of its review on 2022-02-11, it found an EV TLS test certificate showing the wrong jurisdiction state: Utah instead of Delaware, which it said violated SSL Baseline Requirements guideline 9.2.5 for private organizations. IdenTrust said the issue was an oversight when Utah was selected as the jurisdiction state and that it was not caught before certificate approval; it also stated the problem occurred only on the revoked EV TLS test certificate. In response, IdenTrust updated its validation procedure for private organizations, including adding a digitally signed checklist process that must be completed by a different registration agent (effective 2022-02-17), and it replaced the set of EV TLS test certificates on its test webpage. The CA reported no pending actions other than including the incident report in its annual WebTrust audit. Mozilla asked whether any remaining issues needed discussion, and the bug was marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:16 UTC Revised: 2026-06-16 19:23 UTC Confidence: 0.90 5 comments
Chronology
  1. IdenTrust discovered an EV TLS test certificate discrepancy showing Utah instead of Delaware jurisdiction state during an internal CAB Forum compliance review.
  2. IdenTrust updated its validation procedure for private organizations regarding address state and jurisdiction of incorporation state requirements.
  3. IdenTrust made the enhanced EV validation checklist process effective, requiring a digitally signed checklist completed by a different agent.
  4. IdenTrust replaced the EV TLS test certificates on its IdenTrust TLS/SSL Certificates Test webpage.
  5. IdenTrust stated there were no pending actions other than including the incident report in its annual WebTrust audit.
Thread Activity
  1. IdenTrust Services, LLC — IdenTrust disclosed that it found an EV TLS test certificate with the wrong jurisdiction state (Utah instead of Delaware) and described its timeline and remediation steps, including updated validation procedures and a new signed checklist process.
  2. Community commenter — Mathew Hodson asked whether the provided value (6081405641) was supposed to be a link and referenced Mozilla guidance for incident reporting.
  3. IdenTrust Services, LLC — IdenTrust clarified that the value was intended to be a crt.sh ID and provided the certificate URL on crt.sh.
  4. IdenTrust Services, LLC — IdenTrust stated it had no pending actions for the incident report other than including it in the annual WebTrust audit.
  5. Mozilla representative — Mozilla asked if any remaining issues needed discussion and indicated it would look at closing the bug on 2022-03-23.
Participants
IdenTrust Services, LLC Community commenter Mozilla representative
Similar Local Cases
#1895006 RESOLVED Certificate Misissuance Opened 2024-05-03 · Closed 2024-08-23 · 100% similar
IdenTrust: unintended creation of a Root CA certificate
#1756261 RESOLVED Certificate Misissuance Opened 2022-02-18 · Closed 2023-02-22 · 100% similar
IdenTrust: EV TLS certificate with invalid Jurisdiction state for government entity
#1853783 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2023-09-18 · Closed 2025-03-20 · 98% similar
IdenTrust: S/MIME certificates issued in violation of New S/MIME Baseline Requirements v1.0
#1910195 RESOLVED Certificate Misissuance Self Reported Incident Opened 2024-07-26 · Closed 2024-09-06 · 97% similar
IdenTrust: Invalid special characters in S/MIME Certificates
#1930029 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-11-08 · Closed 2025-02-19 · 97% similar
IdenTrust: Approval of TLS certificate renewal without domain validation
#1831004 RESOLVED Certificate Misissuance Opened 2023-05-02 · Closed 2024-05-09 · 97% similar
IdenTrust: duplicate Certificate in error flagged by OCSP Watch
#1663080 RESOLVED Certificate Misissuance Opened 2020-09-03 · Closed 2023-02-22 · 96% similar
IdenTrust: Issuance of certificates greater than 398 days
#1718552 RESOLVED Certificate Misissuance Opened 2021-06-28 · Closed 2023-02-22 · 95% similar
IdenTrust: Certificates with Invalid values for stateOrProvinceName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action