← IdenTrust Services, LLC cases
Bugzilla #1758027 Self Incident Disclosure

IdenTrust: Pre-certificates without a final certificate showing OCSP error

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

IdenTrust reported an internal compliance issue involving pre-certificates for which no final certificate was issued, resulting in OCSP responses of "unauthorized". During an internal review, IdenTrust found 4,543 such pre-certificates and later identified an additional 124, for 4,667 unexpired pre-certificates issued between 2021-04-07 and 2022-03-11. IdenTrust stated that these pre-certificates were submitted to CT logs and that its OCSP responders returned "unauthorized" because the pre-certificates were not registered in the OCSP database when the final certificate was not issued. IdenTrust said it violated CA/B Forum Baseline Requirements section 4.10.2 and Mozilla recommended practice for handling pre-certificates. In response, IdenTrust registered the identified pre-certificates in the OCSP DB and confirmed valid OCSP responses for each pre-certificate, and it deployed a permanent fix by updating the TLS issuance process to register each pre-certificate into the OCSP DB regardless of whether a final certificate will be issued. IdenTrust stated that it successfully deployed the solution and considered the issue resolved on 2022-05-23, and Mozilla indicated it would close the bug on or about 2022-05-27 unless further questions arose.

Model: gpt-5.4-nano Generated: 2026-06-13 21:17 UTC Revised: 2026-06-16 19:23 UTC Confidence: 0.90 9 comments
Chronology
  1. IdenTrust began issuing pre-certificates that later were found to lack corresponding final certificates and OCSP entries.
  2. IdenTrust discovered pre-certificates with missing OCSP status entries during an internal review.
  3. IdenTrust put in place a monitoring utility to check every 24 hours for pre-certificates missing a final certificate and remediate OCSP status.
  4. IdenTrust planned and then deployed the permanent fix to register pre-certificates in the OCSP DB regardless of final certificate issuance.
  5. IdenTrust reported the permanent solution was successfully deployed and considered the issue resolved.
Thread Activity
  1. IdenTrust Services, LLC — IdenTrust reported that internal review found 4,543 pre-certificates with "unauthorized" OCSP responses where no final certificate was issued, and said it was investigating and would supply a full incident report.
  2. IdenTrust Services, LLC — IdenTrust said it had made progress updating the abandoned pre-certificates to reflect valid OCSP status and would post the complete incident report by 2022-03-15.
  3. IdenTrust Services, LLC — IdenTrust provided the incident report details, including discovery of 4,667 cases, the "unauthorized" OCSP responses, the stated Baseline Requirements violation, and remediation and prevention steps.
  4. IdenTrust Services, LLC — IdenTrust attached an Excel file listing the problematic pre-certificates.
  5. IdenTrust Services, LLC — IdenTrust stated that as of 2022-03-16 it had a monitoring utility checking every 24 hours for pre-certificates missing a final certificate and remediating OCSP status.
  6. IdenTrust Services, LLC — IdenTrust reported the permanent solution was in QA testing and expected to be in production by 2022-05-23.
  7. IdenTrust Services, LLC — IdenTrust said it was on track to deploy the permanent solution on 2022-05-21 and would post a status update by 2022-05-23.
  8. IdenTrust Services, LLC — IdenTrust stated it successfully deployed the solution and considered the issue resolved.
  9. Mozilla representative — Mozilla indicated it would close the bug on or about 2022-05-27 unless there were additional questions or issues.
Participants
IdenTrust Services, LLC Mozilla representative
External References
Similar Local Cases
#1831004 RESOLVED Certificate Misissuance Opened 2023-05-02 · Closed 2024-05-09 · 65% similar
IdenTrust: duplicate Certificate in error flagged by OCSP Watch
#1905446 RESOLVED Incident Opened 2024-06-28 · Closed 2024-12-09 · 64% similar
IdenTrust: Unauthorized OCSP response on a Timestamp certificate
#1910195 RESOLVED Certificate Misissuance Self Reported Incident Opened 2024-07-26 · Closed 2024-09-06 · 64% similar
IdenTrust: Invalid special characters in S/MIME Certificates
#1756850 RESOLVED Certificate Misissuance Opened 2022-02-23 · Closed 2023-02-22 · 64% similar
IdenTrust: EV TLS certificate with wrong jurisdiction state for private organization
#1853783 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2023-09-18 · Closed 2025-03-20 · 63% similar
IdenTrust: S/MIME certificates issued in violation of New S/MIME Baseline Requirements v1.0
#1653680 RESOLVED Self Incident Disclosure Opened 2020-07-17 · Closed 2023-02-22 · 63% similar
IdenTrust: OCSP Responder missing id-pkix-ocsp-nocheck
#1753287 RESOLVED Incident Opened 2022-02-02 · Closed 2024-07-08 · 63% similar
IdenTrust: Validation Source for EV Certificates not Publicly Disclosed
#1756261 RESOLVED Certificate Misissuance Opened 2022-02-18 · Closed 2023-02-22 · 63% similar
IdenTrust: EV TLS certificate with invalid Jurisdiction state for government entity

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action