← IdenTrust Services, LLC cases
Bugzilla #1861782 Ca Certificate Compliance Certificate Misissuance

IdenTrust: S/MIME certificates with Invalid document Identification Scheme

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

IdenTrust reported an incident affecting its S/MIME “Basic Assurance” certificates (S/MIME Individual-Validated for non-Enterprise customers). The company said that after a software release deployed on 2023-10-19, customers retrieving “S/MIME Mailbox-Validated” certificates encountered errors because individual identity details were missing. IdenTrust determined that the control for individual identity validation was not required for Mailbox-Validated certificates, and that the software change mistakenly affected Mailbox-Validated certificates. IdenTrust suspended the offering of Basic Assurance certificates, identified 80 active Basic Assurance certificates with an identity validation scheme that was not S/MIME BR Compliant, and reversed the software change control. IdenTrust notified affected customers of certificate revocation no later than 2023-10-27 and confirmed that all affected certificates were revoked by 2023-10-27 18:30. The bug was resolved as FIXED, with the CA stating there were no further pending actions and requesting closure.

Model: gpt-5.4-nano Generated: 2026-06-13 21:22 UTC Revised: 2026-06-16 19:26 UTC Confidence: 0.86 4 comments
Chronology
  1. A software release was deployed that mistakenly affected S/MIME Mailbox-Validated certificates.
  2. IdenTrust confirmed customer errors, suspended the affected certificate offering, and identified 80 active non-compliant certificates.
  3. IdenTrust confirmed all affected certificates were revoked.
Thread Activity
  1. IdenTrust Services, LLC — Created an incident report describing the cause (a software change affecting Mailbox-Validated certificates), the impact, and the revocation timeline, and attached a spreadsheet of revoked certificates.
  2. IdenTrust Services, LLC — Stated there were no further pending actions for the issue.
  3. IdenTrust Services, LLC — Asked Mozilla to close the ticket.
  4. Mozilla representative — Indicated the ticket would be closed on Wed 3-Jan-2024 unless there were objections.
Participants
IdenTrust Services, LLC Mozilla representative
External References
Similar Local Cases
#1635279 RESOLVED Certificate Misissuance Opened 2020-05-04 · Closed 2023-02-22 · 97% similar
IdenTrust: Incorrect Subject Details for HydrantId
#1850807 RESOLVED Certificate Misissuance Opened 2023-08-30 · Closed 2023-09-29 · 96% similar
IdenTrust: basicConstraints not flagged "Critical" Per Certification Practices Statement
#1897569 RESOLVED Certificate Misissuance Opened 2024-05-17 · Closed 2024-08-23 · 95% similar
IdenTrust: TLS ICA with User Notice in Policy Qualifier
#1669594 RESOLVED Certificate Misissuance Opened 2020-10-06 · Closed 2023-02-22 · 95% similar
IdenTrust: Issuance of Subordinate CA’s Without EKU
#1796715 RESOLVED Certificate Misissuance Opened 2022-10-20 · Closed 2023-02-22 · 95% similar
IdenTrust: Mis-Issued EV Code Signing Certificate
#1853783 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2023-09-18 · Closed 2025-03-20 · 87% similar
IdenTrust: S/MIME certificates issued in violation of New S/MIME Baseline Requirements v1.0
#1919162 RESOLVED Certificate Misissuance Opened 2024-09-16 · Closed 2024-12-09 · 85% similar
IdenTrust: TLS Certificates with outdated certificate profile
#1861783 RESOLVED Ca Certificate Compliance Opened 2023-10-28 · Closed 2024-01-04 · 80% similar
IdenTrust: S/MIME Certificates issued without CAB Forum OID

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action