← IdenTrust Services, LLC cases
Bugzilla #1794047 Revocation Issue Self Reported Incident

IdenTrust: Missing Revocation Reasons in CRL

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

IdenTrust reported a compliance issue it discovered in its own certificate revocation lists (CRLs). During a routine quality check, it found that a CRL created on 10/2/2022 for the “HydrantID Server CA O1” ICA was missing the revocation reasons for all listed revoked certificates, which it stated violates Mozilla Root Store Policy Section 6.1.1 and IdenTrust CPS Section 4.9.3. IdenTrust said it confirmed that current CRLs are correct and that the initial indications pointed to a software change control deployed on 10/1/2022. In its incident report, IdenTrust attributed the problem to a database update during the weekend change control that did not execute as expected, and it remediated by correctly executing the database update. It also stated that it added a step for future change controls to validate the presence of revocation reasons on CRLs. The bug was resolved as FIXED, and IdenTrust indicated there were no additional items for the issue.

Model: gpt-5.4-nano Generated: 2026-06-13 21:18 UTC Revised: 2026-06-16 19:24 UTC Confidence: 0.90 4 comments
Chronology
  1. IdenTrust deployed a release intended to update revocation reason codes for Mozilla Root Store Policy v2.8 compliance.
  2. A CRL for “HydrantID Server CA O1” was generated with missing revocation reasons.
  3. IdenTrust investigated and remediated by correctly executing the database update that had failed to run as expected.
  4. IdenTrust confirmed the 10/2/2022 CRL for “HydrantID Server CA O1” was missing revocation reasons.
Thread Activity
  1. IdenTrust Services, LLC — IdenTrust reported that it discovered at least one CRL with missing revocation reasons for all listed revoked certificates and said it would provide a formal incident report by 10/14/2022.
  2. IdenTrust Services, LLC — IdenTrust provided a full incident report describing the routine quality check discovery, the timeline of the failed database update during change control, remediation, and a future validation step for CRL revocation reasons.
  3. IdenTrust Services, LLC — IdenTrust stated it had no additional items for the issue.
  4. Mozilla representative — Mozilla indicated it would close the bug on or about 2-Nov-2022.
Participants
IdenTrust Services, LLC Mozilla representative
External References
Similar Local Cases
#1910195 RESOLVED Certificate Misissuance Self Reported Incident Opened 2024-07-26 · Closed 2024-09-06 · 98% similar
IdenTrust: Invalid special characters in S/MIME Certificates
#1526099 RESOLVED Self Reported Incident Revocation Issue Audit Finding Opened 2019-02-07 · Closed 2023-02-22 · 98% similar
IdenTrust: Discrepancy in values of address fields within CN of SSL Certificates
#1853783 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2023-09-18 · Closed 2025-03-20 · 96% similar
IdenTrust: S/MIME certificates issued in violation of New S/MIME Baseline Requirements v1.0
#1930029 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-11-08 · Closed 2025-02-19 · 96% similar
IdenTrust: Approval of TLS certificate renewal without domain validation
#1933353 RESOLVED Self Reported Incident Opened 2024-11-25 · Closed 2025-03-21 · 96% similar
IdenTrust: Incorrect response for OCSP validation
#1598807 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-11-23 · Closed 2023-02-22 · 94% similar
IdenTrust: Undisclosed Unrevoked ICAs
#2026351 RESOLVED Self Reported Incident Certificate Misissuance Opened 2026-03-25 · Closed 2026-05-18 · 90% similar
Identrust: Root CrossSign, of dedicated Roots, missing EKU
#1991215 RESOLVED Self Reported Incident Opened 2025-09-26 · Closed 2025-11-21 · 88% similar
IdenTrust: ICA with invalid CDP

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action