← IdenTrust Services, LLC cases
Bugzilla #1861783 Ca Certificate Compliance

IdenTrust: S/MIME Certificates issued without CAB Forum OID

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

IdenTrust reported that, while inspecting Enterprise certificates on 2023-10-23, it discovered that 1,135 S/MIME certificates issued to four Enterprise customers were missing the expected CA/B Forum OID after 2023-08-31. The CA stated that some customers were supposed to have been moved to a different certificate program and were not expected to use the publicly trusted ICA, but the API access to that publicly trusted ICA had not been disabled. Id enTrust disabled the API for the four affected Enterprise customers on 2023-10-23 21:30, notified customers of the revocation requirement by 2023-10-27, and confirmed that all affected certificates were revoked by 2023-10-27 23:30. The CA’s root cause analysis attributed the issue to not turning off an API that was no longer meant to be in use. The thread indicates there were no further pending actions and Mozilla planned to close the ticket unless there were objections. The bug was resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:22 UTC Revised: 2026-06-16 19:26 UTC Confidence: 0.86 4 comments
Chronology
  1. IdenTrust discovered 1,135 S/MIME certificates missing the expected CA/B Forum OID and identified four affected Enterprise customers.
  2. IdenTrust disabled the API for the four affected Enterprise customers.
  3. IdenTrust confirmed all affected certificates were revoked.
Thread Activity
  1. IdenTrust Services, LLC — Created the incident report attachment, describing discovery of missing S/MIME CA/B Forum OID, deactivation of the relevant API, customer notification of revocation requirements, and confirmation that all affected certificates were revoked.
  2. IdenTrust Services, LLC — Stated there were no further pending actions for the issue.
  3. IdenTrust Services, LLC — Asked Mozilla to close the ticket.
  4. Mozilla representative — Indicated intent to close the ticket on Wed 3-Jan-2024 unless there were objections.
Participants
IdenTrust Services, LLC Mozilla representative
External References
Similar Local Cases
#1853783 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2023-09-18 · Closed 2025-03-20 · 98% similar
IdenTrust: S/MIME certificates issued in violation of New S/MIME Baseline Requirements v1.0
#1883792 RESOLVED Ca Certificate Compliance Opened 2024-03-05 · Closed 2024-06-30 · 97% similar
IdenTrust: Temporary Errors in Test Website Certificates
#1744627 RESOLVED Ca Certificate Compliance Opened 2021-12-06 · Closed 2023-02-22 · 96% similar
IdenTrust: Issuance of OV SSL Certificate with doc vetting older than 398 days
#1749089 RESOLVED Ca Certificate Compliance Opened 2022-01-08 · Closed 2023-02-22 · 96% similar
IdenTrust: OCSP Signer Certificate Missing No-Check Extension
#1772633 RESOLVED Ca Certificate Compliance Opened 2022-06-03 · Closed 2023-02-22 · 96% similar
IdenTrust: OCSP responses for subordinate CA exceed the validity period per CPS guidelines
#1598807 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-11-23 · Closed 2023-02-22 · 94% similar
IdenTrust: Undisclosed Unrevoked ICAs
#1734917 RESOLVED Ca Certificate Compliance Opened 2021-10-08 · Closed 2023-02-22 · 94% similar
IdenTrust: Mis-Issued EV Certificates
#1876871 RESOLVED Ca Certificate Compliance Opened 2024-01-26 · Closed 2024-06-30 · 88% similar
IdenTrust: test certificates inadvertently published in production environment

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action