← IdenTrust Services, LLC cases
Bugzilla #1861782
Certificate Problem Report
IdenTrust: S/MIME certificates with Invalid document Identification Scheme
RESOLVED
FIXED
IdenTrust Services, LLC
AI Summary
IdenTrust Services, LLC identified an issue with S/MIME Mailbox-Validated certificates that arose from a software release on October 19, 2023. This release inadvertently required individual identity validation for these certificates, which do not require such validation. The company suspended the offering of Basic Assurance certificates and revoked 80 affected certificates within five days. Although the revocation process was swift, some customers expressed dissatisfaction with the timeline.
Chronology
- Customer support confirmed issues with S/MIME Mailbox-Validated certificates.
- Investigation began and cause of error was determined.
- Suspended offering of Basic Assurance certificates.
- All affected certificates were confirmed revoked.
Participants
roots@identrust.com
bwilson@mozilla.com
External References
Similar Local Cases
IdenTrust: EV TLS certificate with invalid Jurisdiction state for government entity
IdenTrust: TLS Certificates with outdated certificate profile
IdenTrust: Unauthorized OCSP response on a Timestamp certificate
IdenTrust: Undisclosed Unrevoked ICAs
IdenTrust: Expired CRL served
IdenTrust: Unavailable CRL and OCSP Responders
IdenTrust: CRL Potential Publication Delay due to Cache
IdenTrust: Discrepancy in values of address fields within CN of SSL Certificates