← IdenTrust Services, LLC cases
Bugzilla #1876871 Ca Certificate Compliance

IdenTrust: test certificates inadvertently published in production environment

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

IdenTrust reported that some test S/MIME and TLS certificates were mistakenly issued in its CA production environment instead of the designated CA test environment, bypassing the CA/B Forum BRs vetting processes. IdenTrust stated that the uncovered certificates were automatically revoked within minutes (and in some cases within seconds) of issuance, and that it believed the impact on trustworthiness was minimal due to the short lifetime. IdenTrust later confirmed the root cause as QA test automation scripts being run in the production environment, and identified that QA had temporary access to the production environment certificate application API for one-time work that had already been completed. As remediation, IdenTrust revoked QA access to the production environment and blocked reauthorization going forward using technical means, and it performed a comprehensive examination of its certificate database to confirm no additional certificates were issued in this manner. IdenTrust disclosed the incident to CCADB via this bug report and later stated it had no further remediation actions pending. Mozilla indicated it would close the bug on or about March 15, 2024 unless additional items were discussed. The bug was resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:24 UTC Revised: 2026-06-16 19:26 UTC Confidence: 0.90 5 comments
Chronology
  1. IdenTrust confirmed that test S/MIME certificates containing test data were inadvertently published in the production environment instead of the test environment.
  2. IdenTrust’s investigation identified additional inadvertently issued S/MIME certificates and a similarly issued TLS certificate, all revoked shortly after publication.
  3. IdenTrust determined QA test scripts were mistakenly published in production and identified temporary QA API access as the source of the wrong-environment issue.
  4. IdenTrust completed its comprehensive analysis and found no evidence of other S/MIME or TLS certificates issued in this manner.
  5. IdenTrust stated there were no further remediation actions pending for the issue.
Thread Activity
  1. IdenTrust Services, LLC — IdenTrust opened a preliminary incident report stating test S/MIME and TLS certificates were mistakenly issued in production instead of the test environment and that they were revoked within minutes.
  2. IdenTrust Services, LLC — IdenTrust said it would post a complete incident report no later than February 16, 2024.
  3. IdenTrust Services, LLC — IdenTrust provided a complete incident report with a timeline, stated the root cause (QA automation scripts run in production), described remediation (revoking QA production access and blocking reauthorization), and reported that a database examination found no other affected certificates.
  4. IdenTrust Services, LLC — IdenTrust stated it had no further remediation actions pending for this issue.
  5. Mozilla representative — Mozilla indicated it would close the bug on or about Friday, 15-March-2024 unless additional items were discussed.
Participants
IdenTrust Services, LLC Mozilla representative
External References
Similar Local Cases
#1861783 RESOLVED Ca Certificate Compliance Opened 2023-10-28 · Closed 2024-01-04 · 88% similar
IdenTrust: S/MIME Certificates issued without CAB Forum OID
#1744627 RESOLVED Ca Certificate Compliance Opened 2021-12-06 · Closed 2023-02-22 · 88% similar
IdenTrust: Issuance of OV SSL Certificate with doc vetting older than 398 days
#1853783 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2023-09-18 · Closed 2025-03-20 · 86% similar
IdenTrust: S/MIME certificates issued in violation of New S/MIME Baseline Requirements v1.0
#1883792 RESOLVED Ca Certificate Compliance Opened 2024-03-05 · Closed 2024-06-30 · 85% similar
IdenTrust: Temporary Errors in Test Website Certificates
#1772633 RESOLVED Ca Certificate Compliance Opened 2022-06-03 · Closed 2023-02-22 · 85% similar
IdenTrust: OCSP responses for subordinate CA exceed the validity period per CPS guidelines
#1598807 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-11-23 · Closed 2023-02-22 · 84% similar
IdenTrust: Undisclosed Unrevoked ICAs
#1734917 RESOLVED Ca Certificate Compliance Opened 2021-10-08 · Closed 2023-02-22 · 84% similar
IdenTrust: Mis-Issued EV Certificates
#1749089 RESOLVED Ca Certificate Compliance Opened 2022-01-08 · Closed 2023-02-22 · 84% similar
IdenTrust: OCSP Signer Certificate Missing No-Check Extension

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action