IdenTrust: EV TLS test certificate issued with wrong jurisdiction state for private organization (resolved)
IdenTrust Services, LLC reported a compliance discrepancy it discovered during an internal review of CAB Forum compliance. The CA stated that, as part of its review on 2022-02-11, it found an EV TLS test certificate showing the wrong jurisdiction state: Utah instead of Delaware, which it said violated SSL Baseline Requirements guideline 9.2.5 for private organizations. IdenTrust said the issue was an oversight when Utah was selected as the jurisdiction state and that it was not caught before certificate approval; it also stated the problem occurred only on the revoked EV TLS test certificate. In response, IdenTrust updated its validation procedure for private organizations, including adding a digitally signed checklist process that must be completed by a different registration agent (effective 2022-02-17), and it replaced the set of EV TLS test certificates on its test webpage. The CA reported no pending actions other than including the incident report in its annual WebTrust audit. Mozilla asked whether any remaining issues needed discussion, and the bug was marked RESOLVED with resolution FIXED.
- IdenTrust discovered an EV TLS test certificate discrepancy showing Utah instead of Delaware jurisdiction state during an internal CAB Forum compliance review.
- IdenTrust updated its validation procedure for private organizations regarding address state and jurisdiction of incorporation state requirements.
- IdenTrust made the enhanced EV validation checklist process effective, requiring a digitally signed checklist completed by a different agent.
- IdenTrust replaced the EV TLS test certificates on its IdenTrust TLS/SSL Certificates Test webpage.
- IdenTrust stated there were no pending actions other than including the incident report in its annual WebTrust audit.
- IdenTrust Services, LLC — IdenTrust disclosed that it found an EV TLS test certificate with the wrong jurisdiction state (Utah instead of Delaware) and described its timeline and remediation steps, including updated validation procedures and a new signed checklist process.
- Community commenter — Mathew Hodson asked whether the provided value (6081405641) was supposed to be a link and referenced Mozilla guidance for incident reporting.
- IdenTrust Services, LLC — IdenTrust clarified that the value was intended to be a crt.sh ID and provided the certificate URL on crt.sh.
- IdenTrust Services, LLC — IdenTrust stated it had no pending actions for the incident report other than including it in the annual WebTrust audit.
- Mozilla representative — Mozilla asked if any remaining issues needed discussion and indicated it would look at closing the bug on 2022-03-23.