← IdenTrust Services, LLC cases
Bugzilla #1838315 Ca Security Vulnerability Incident

IdenTrust: Certificate with missing details flagged by OCSP Watch

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

IdenTrust reported that, during routine monitoring on June 7, 2023, it detected an IdenTrust-issued certificate flagged by the SSLMATE OCSP Watch monitoring tool as requiring attention. Id enTrust stated the issue was corrected the same day, and that investigation found the flagging was caused by a system outage that resulted in issuance of a precertificate without a serial number, leading to an unknown OCSP status. Id enTrust cited the Subscriber (Server) Certificate Profile in B.R. Section 7.1.2.7, stating that inclusion of a serial number is mandatory. The CA said it would prevent recurrence by enhancing its code with a stronger locking mechanism to avoid multiple retries during certificate retrieval that could lead to incomplete certificates, with an implementation target of September 30, 2023 and monthly progress updates. Id enTrust later reported that the code revision was tested and deployed on 9/30/2023 and was working as expected, and it considered the issue closed as completed. Mozilla indicated it would close the bug on 11-Oct-2023 unless questions remained, and the bug is resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:19 UTC Revised: 2026-06-16 19:25 UTC Confidence: 0.90 9 comments
Chronology
  1. IdenTrust detected an OCSP Watch flag for an IdenTrust-issued certificate and corrected the discrepancy the same day.
  2. IdenTrust deployed a code change intended to prevent recurrence of incomplete certificate issuance during retrieval retries.
  3. IdenTrust confirmed the deployed code was working as expected and marked the issue closed.
Thread Activity
  1. IdenTrust Services, LLC — IdenTrust said it noticed an IdenTrust-issued certificate in the SSLMATE OCSP watch monitor tool on June 7, 2023, that the issue was corrected the same day, and that it would supply a complete incident report by June 24, 2023.
  2. IdenTrust Services, LLC — IdenTrust provided details: routine monitoring detected the issue on June 7, it was due to a system outage causing a precertificate without a serial number, and it described a timeline and planned remediation via stronger locking to avoid multiple retrieval retries.
  3. IdenTrust Services, LLC — IdenTrust reported it was on track to deploy the fix and would provide a status update by August 31, 2023.
  4. IdenTrust Services, LLC — IdenTrust reported it remained on track to deploy the fix by the end of September and would provide a status update by September 30, 2023.
  5. Internet Security Research Group — Let’s Encrypt’s pp orada asked whether IdenTrust could attach the precertificate generated without the serial number.
  6. IdenTrust Services, LLC — IdenTrust explained that a hardware malfunction led to resource limitations and performance issues, multiple retrieval attempts generated a precertificate whose serial number was overwritten, and it published the precertificate to CT (crt.sh link provided).
  7. IdenTrust Services, LLC — IdenTrust stated the code revision was tested and on track for the September 30 release date, with a final update planned for October 2.
  8. IdenTrust Services, LLC — IdenTrust confirmed the code was successfully deployed on 9/30/2023 and was working as expected, and it considered the issue closed as completed.
  9. Mozilla representative — Mozilla stated it would close the bug on 11-Oct-2023 unless there were questions or concerns still to address.
Participants
IdenTrust Services, LLC Internet Security Research Group Mozilla representative
External References
Similar Local Cases
#1905446 RESOLVED Incident Opened 2024-06-28 · Closed 2024-12-09 · 98% similar
IdenTrust: Unauthorized OCSP response on a Timestamp certificate
#1900492 RESOLVED Incident Opened 2024-06-03 · Closed 2026-06-10 · 96% similar
IdenTrust: Invalid OrganizationIdentifier in S/MIME certificates
#1709192 RESOLVED Incident Opened 2021-05-03 · Closed 2023-02-22 · 94% similar
IdenTrust: Unavailable CRL for IdenTrust ‘DST Root CA X3’.
#1753287 RESOLVED Incident Opened 2022-02-02 · Closed 2024-07-08 · 94% similar
IdenTrust: Validation Source for EV Certificates not Publicly Disclosed
#1542082 RESOLVED Incident Self Reported Incident Opened 2019-04-04 · Closed 2023-02-22 · 88% similar
IdenTrust: Failure to disclose Unconstrained intermediate Within 7 Days
#2016585 RESOLVED Self Reported Incident Incident Opened 2026-02-12 · Closed 2026-06-15 · 87% similar
IdenTrust: Test Certificates from cross-signed roots not disclosed in CT Logs
#2025595 RESOLVED Self Reported Incident Incident Opened 2026-03-23 · Closed 2026-05-18 · 87% similar
IdenTrust: Delay in updating a Bug 2014609 - Next update
#2014590 RESOLVED Self Reported Incident Incident Opened 2026-02-04 · Closed 2026-04-23 · 86% similar
IdenTrust: Unauthorized OCSP responses for cross-signed roots

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action