IdenTrust: S/MIME certificates with Invalid document Identification Scheme
IdenTrust reported an incident affecting its S/MIME “Basic Assurance” certificates (S/MIME Individual-Validated for non-Enterprise customers). The company said that after a software release deployed on 2023-10-19, customers retrieving “S/MIME Mailbox-Validated” certificates encountered errors because individual identity details were missing. IdenTrust determined that the control for individual identity validation was not required for Mailbox-Validated certificates, and that the software change mistakenly affected Mailbox-Validated certificates. IdenTrust suspended the offering of Basic Assurance certificates, identified 80 active Basic Assurance certificates with an identity validation scheme that was not S/MIME BR Compliant, and reversed the software change control. IdenTrust notified affected customers of certificate revocation no later than 2023-10-27 and confirmed that all affected certificates were revoked by 2023-10-27 18:30. The bug was resolved as FIXED, with the CA stating there were no further pending actions and requesting closure.
- A software release was deployed that mistakenly affected S/MIME Mailbox-Validated certificates.
- IdenTrust confirmed customer errors, suspended the affected certificate offering, and identified 80 active non-compliant certificates.
- IdenTrust confirmed all affected certificates were revoked.
- IdenTrust Services, LLC — Created an incident report describing the cause (a software change affecting Mailbox-Validated certificates), the impact, and the revocation timeline, and attached a spreadsheet of revoked certificates.
- IdenTrust Services, LLC — Stated there were no further pending actions for the issue.
- IdenTrust Services, LLC — Asked Mozilla to close the ticket.
- Mozilla representative — Indicated the ticket would be closed on Wed 3-Jan-2024 unless there were objections.