← IdenTrust Services, LLC cases
Bugzilla #1853783 Ca Certificate Compliance Certificate Misissuance Self Reported Incident

IdenTrust: S/MIME certificates issued in violation of New S/MIME Baseline Requirements v1.0

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

IdenTrust reported that, during normal operations, it discovered on 06 September 2023 that 114 S/MIME certificates had been issued after 01 September 2023 in violation of certificate details in the CA/B Forum S/MIME Baseline Requirements version 1.0 that took effect that day. The certificates were issued in violation of the 112-bit entropy requirements (68 certificates) and Subject DN attribute requirements for sponsor-validated (27 certificates) and individual-validated profiles (19 certificates). IdenTrust stopped issuance on 06 September 2023 and completed sending revocation notices to affected certificate holders by 07 September 2023. IdenTrust deployed a hotfix on 11 September 2023 to fix the entropy size issue and updated certificate profiles to include the subject givenName and surname attributes, then revoked all affected certificates and enabled a new issuance process for mailbox-validated S/MIME certificates on 11 September 2023. The thread also includes updates that IdenTrust implemented an updated S/MIME linting tool, with successful implementation reported on 20 January 2024 and the issue considered resolved. Mozilla indicated it would close the bug on 26 January 2024, and the bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:20 UTC Revised: 2026-06-16 19:25 UTC Confidence: 0.90 7 comments
Chronology
  1. Improper S/MIME issuance began, before IdenTrust discovered the compliance problem.
  2. IdenTrust discovered that 114 S/MIME certificates had been issued in violation of S/MIME Baseline Requirements v1.0 and stopped issuance.
  3. IdenTrust completed sending revocation notices to affected certificate holders.
  4. IdenTrust deployed a hotfix, updated certificate profiles, revoked affected certificates, and enabled a new issuance process.
  5. IdenTrust implemented the updated S/MIME linting tool and confirmed its functionality.
Thread Activity
  1. IdenTrust Services, LLC — IdenTrust disclosed the incident, including the number of affected S/MIME certificates, the specific S/MIME Baseline Requirements sections violated, and the remediation timeline (stopping issuance, revocations, hotfix/profile updates, and re-enabling issuance).
  2. IdenTrust Services, LLC — IdenTrust created an attachment listing the IdenTrust S/MIME misissued certificates.
  3. IdenTrust Services, LLC — IdenTrust stated it was on track to implement an updated S/MIME linting tool no later than January 2024 and would provide a next update by November 30, 2023.
  4. IdenTrust Services, LLC — IdenTrust reiterated it was on track to implement the updated S/MIME linting tool by January 31, 2024 and would post a status update by December 29, 2023.
  5. IdenTrust Services, LLC — IdenTrust provided another status update, again stating it would post the next update by January 31, 2024.
  6. IdenTrust Services, LLC — IdenTrust reported it successfully implemented the updated S/MIME linting tool on 1/20/2024, confirmed functionality, and considered the issue resolved with no outstanding tasks.
  7. Mozilla representative — Mozilla stated it would close the bug on Friday, 26-Jan-2024.
Participants
IdenTrust Services, LLC Mozilla representative
External References
Similar Local Cases
#1910195 RESOLVED Certificate Misissuance Self Reported Incident Opened 2024-07-26 · Closed 2024-09-06 · 100% similar
IdenTrust: Invalid special characters in S/MIME Certificates
#1930029 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-11-08 · Closed 2025-02-19 · 100% similar
IdenTrust: Approval of TLS certificate renewal without domain validation
#1598807 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-11-23 · Closed 2023-02-22 · 100% similar
IdenTrust: Undisclosed Unrevoked ICAs
#2026351 RESOLVED Self Reported Incident Certificate Misissuance Opened 2026-03-25 · Closed 2026-05-18 · 99% similar
Identrust: Root CrossSign, of dedicated Roots, missing EKU
#1861783 RESOLVED Ca Certificate Compliance Opened 2023-10-28 · Closed 2024-01-04 · 98% similar
IdenTrust: S/MIME Certificates issued without CAB Forum OID
#1756850 RESOLVED Certificate Misissuance Opened 2022-02-23 · Closed 2023-02-22 · 98% similar
IdenTrust: EV TLS certificate with wrong jurisdiction state for private organization
#1831004 RESOLVED Certificate Misissuance Opened 2023-05-02 · Closed 2024-05-09 · 98% similar
IdenTrust: duplicate Certificate in error flagged by OCSP Watch
#2014609 RESOLVED Self Reported Incident Certificate Misissuance Opened 2026-02-05 · Closed 2026-04-11 · 97% similar
IdenTrust: Cross-signed root certificate mis-issuance

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action