← IdenTrust Services, LLC cases
Bugzilla #1850807 Certificate Misissuance

IdenTrust: basicConstraints not flagged "Critical" Per Certification Practices Statement

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

IdenTrust reported that, during a routine review on 2023-08-28, it discovered EV TLS certificates containing the "basicConstraints" extension but not marked as "critical," which it stated violates its TrustID CPS. The CA said it found 1,187 affected EV TLS certificates and began investigating scope the same day. On 2023-08-29, IdenTrust updated the certificate profile for issuing ICA EV TLS certificates by removing the "basicConstraints" extension to stop further misissuance. IdenTrust also began outreach to affected customers for revocation and replacement, and it reported that 107 of the affected certificates had been revoked and 33 had expired as of 2023-09-15. Mozilla asked about remediation and whether any outstanding items remained, and IdenTrust confirmed the issue could be closed; Mozilla then indicated it would close the bug. The bug is resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:19 UTC Revised: 2026-06-16 19:25 UTC Confidence: 0.88 8 comments
Chronology
  1. IdenTrust discovered that EV TLS certificates included basicConstraints without the critical flag, violating its TrustID CPS.
  2. IdenTrust updated the EV TLS certificate profile to remove the basicConstraints extension and stop further misissuance.
  3. IdenTrust posted the initial issue report in Bugzilla.
  4. IdenTrust reported counts of revoked and expired affected certificates as of this date.
  5. Mozilla and IdenTrust agreed the remediation was complete and the bug could be closed.
Thread Activity
  1. IdenTrust Services, LLC — IdenTrust stated it discovered the CPS/profile mismatch for EV TLS certificates on 2023-08-28, corrected the certificate profile on 2023-08-29 to stop further misissuances, and said it would disclose a full incident report by 2023-09-15.
  2. IdenTrust Services, LLC — IdenTrust provided a detailed timeline and stated it found 1,187 affected EV TLS certificates with basicConstraints present but not marked critical, including that quarterly self-audits failed to identify the discrepancy.
  3. IdenTrust Services, LLC — IdenTrust attached CSV files listing valid, revoked, and expired affected certificates.
  4. Mozilla representative — Mozilla asked whether updating the CPS, written profiles, and code simultaneously would be better and stated it believed there were no outstanding remediation items aside from Bug #1851710.
  5. IdenTrust Services, LLC — IdenTrust confirmed the bug could be closed.
  6. Mozilla representative — Mozilla stated it would close the bug on Friday.
Participants
IdenTrust Services, LLC Mozilla representative
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#1669594 RESOLVED Certificate Misissuance Opened 2020-10-06 · Closed 2023-02-22 · 100% similar
IdenTrust: Issuance of Subordinate CA’s Without EKU
#1635279 RESOLVED Certificate Misissuance Opened 2020-05-04 · Closed 2023-02-22 · 99% similar
IdenTrust: Incorrect Subject Details for HydrantId
#1897569 RESOLVED Certificate Misissuance Opened 2024-05-17 · Closed 2024-08-23 · 97% similar
IdenTrust: TLS ICA with User Notice in Policy Qualifier
#1861782 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-10-28 · Closed 2024-01-04 · 96% similar
IdenTrust: S/MIME certificates with Invalid document Identification Scheme
#1796715 RESOLVED Certificate Misissuance Opened 2022-10-20 · Closed 2023-02-22 · 96% similar
IdenTrust: Mis-Issued EV Code Signing Certificate
#1919162 RESOLVED Certificate Misissuance Opened 2024-09-16 · Closed 2024-12-09 · 87% similar
IdenTrust: TLS Certificates with outdated certificate profile
#1910195 RESOLVED Certificate Misissuance Self Reported Incident Opened 2024-07-26 · Closed 2024-09-06 · 79% similar
IdenTrust: Invalid special characters in S/MIME Certificates
#1853783 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2023-09-18 · Closed 2025-03-20 · 78% similar
IdenTrust: S/MIME certificates issued in violation of New S/MIME Baseline Requirements v1.0

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action