IdenTrust: basicConstraints not flagged "Critical" Per Certification Practices Statement
IdenTrust reported that, during a routine review on 2023-08-28, it discovered EV TLS certificates containing the "basicConstraints" extension but not marked as "critical," which it stated violates its TrustID CPS. The CA said it found 1,187 affected EV TLS certificates and began investigating scope the same day. On 2023-08-29, IdenTrust updated the certificate profile for issuing ICA EV TLS certificates by removing the "basicConstraints" extension to stop further misissuance. IdenTrust also began outreach to affected customers for revocation and replacement, and it reported that 107 of the affected certificates had been revoked and 33 had expired as of 2023-09-15. Mozilla asked about remediation and whether any outstanding items remained, and IdenTrust confirmed the issue could be closed; Mozilla then indicated it would close the bug. The bug is resolved as FIXED.
- IdenTrust discovered that EV TLS certificates included basicConstraints without the critical flag, violating its TrustID CPS.
- IdenTrust updated the EV TLS certificate profile to remove the basicConstraints extension and stop further misissuance.
- IdenTrust posted the initial issue report in Bugzilla.
- IdenTrust reported counts of revoked and expired affected certificates as of this date.
- Mozilla and IdenTrust agreed the remediation was complete and the bug could be closed.
- IdenTrust Services, LLC — IdenTrust stated it discovered the CPS/profile mismatch for EV TLS certificates on 2023-08-28, corrected the certificate profile on 2023-08-29 to stop further misissuances, and said it would disclose a full incident report by 2023-09-15.
- IdenTrust Services, LLC — IdenTrust provided a detailed timeline and stated it found 1,187 affected EV TLS certificates with basicConstraints present but not marked critical, including that quarterly self-audits failed to identify the discrepancy.
- IdenTrust Services, LLC — IdenTrust attached CSV files listing valid, revoked, and expired affected certificates.
- Mozilla representative — Mozilla asked whether updating the CPS, written profiles, and code simultaneously would be better and stated it believed there were no outstanding remediation items aside from Bug #1851710.
- IdenTrust Services, LLC — IdenTrust confirmed the bug could be closed.
- Mozilla representative — Mozilla stated it would close the bug on Friday.