← D-TRUST cases
Bugzilla #1891225 Self Incident Disclosure

D-Trust: Issuance of 15 TLS certificates with incorrect subject attribute (RDN) order

RESOLVED FIXED D-TRUST
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

D-Trust reported that after September 15, 2023 it issued 15 TLS certificates from the subordinate CA “D-TRUST CA 2-2 EV 2016” where the subject attribute (RDN) order did not match the TLS Baseline Requirements. D-Trust stated that, as part of Ballot SC62, it changed the RDN order for publicly trusted TLS subordinate CAs, but the change was not completed for “D-TRUST CA 2-2 EV 2016,” resulting in a deviation from the TLS BRs. After being made aware, D-Trust stopped production, corrected the configuration, tested in a reference system, and then restarted production. D-Trust informed affected customers and supported them to replace and revoke the affected certificates; D-Trust also revoked the 15 affected certificates. In the thread, D-Trust also discussed follow-up issues related to notification timing and opened a separate bug (1893610) for additional non-compliance discovered during root cause investigation. D-Trust later reported implementing additional measures, including selecting and installing a second linter (PKILint) and running pre-issuance linting with two linters, and asked whether the incident could be closed; Mozilla indicated an intent to close it on or about 7-Aug-2024 unless further items were needed. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:28 UTC Revised: 2026-06-16 10:04 UTC Confidence: 0.90 27 comments
Chronology
  1. Ballot SC62 provisions entered into force for TLS subject attribute (RDN) order requirements.
  2. D-Trust began investigating and stopped production for the affected subordinate CA after identifying the RDN order deviation.
  3. D-Trust revoked all affected TLS certificates.
  4. D-Trust installed PKILint in its production system and began running two linters for pre-issuance linting.
  5. D-Trust reported that all measures were implemented and asked to close the incident.
Thread Activity
  1. D-Trust — Filed a preliminary incident report describing the RDN order deviation, stopping production, correcting configuration, informing customers, and revoking 15 affected TLS certificates.
  2. D-Trust — Reported discovering an additional non-conformity (TLS BR 4.9.5) and opened follow-up incident report bug 1893610, linking to it.
  3. Community commenter — Asked when the full incident report would be posted.
  4. D-Trust — Responded to questions about the incident timeline and linting approach, stating tests were required before tools could be put into operation and describing use of ZLint plus additional measures outside ZLint.
  5. D-Trust — Explained that a final incident report was delayed due to discovery of further non-compliance, opened bug 1893610, and described expanded internal process guidelines and training.
  6. D-Trust — Clarified that no new lints were implemented in ZLint and that internal checks (organizational measures and CA system checks) were established by 2024-05-02.
  7. Bdr representative — Updated that D-Trust decided to implement PKILint as a second linter and was reviewing internal timelines.
  8. D-Trust — Reported successful installation and testing of PKILint in reference and production systems and that two linters are now used for pre-issuance linting.
  9. D-Trust — Reported that all measures were implemented and asked whether the incident could be closed.
  10. Mozilla representative — Stated an intent to close the bug on or about 7-Aug-2024 unless additional items needed discussion or explanation.
Participants
D-Trust Community commenter Bdr representative Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1939809 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-01-03 · Closed 2026-06-12 · 72% similar
D-Trust: QCStatement with http link of PKI Disclosure Statements
#1893610 RESOLVED Self Incident Disclosure Opened 2024-04-26 · Closed 2024-06-30 · 71% similar
D-Trust: Notice to affected Subscriber and person filing CPR not sent within 24 hours
#1884714 RESOLVED Self Incident Disclosure Opened 2024-03-11 · Closed 2024-09-13 · 68% similar
D-Trust: LDAP-URL in Subscriber Certificate Authority Information Access field
#1896190 RESOLVED Ca Certificate Compliance Opened 2024-05-10 · Closed 2024-11-06 · 68% similar
D-Trust: Issuance of an EV certificate containing a mixup of the Subject's postalCode and localityName
#1924385 RESOLVED Ca Certificate Compliance Revocation Issue Closure Request Opened 2024-10-13 · Closed 2025-07-16 · 68% similar
D-Trust: Missed Revocation of TLS certificates affected by Bugzilla 1884714
#1691117 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2021-02-05 · Closed 2023-02-22 · 63% similar
D-TRUST: Certificate with RSA key where modulus is not divisible by 8
#1682270 RESOLVED Ca Certificate Compliance Incident Closure Request Opened 2020-12-14 · Closed 2026-06-12 · 61% similar
D-TRUST: Private Key Disclosed by Customer as Part of CSR
#1793440 RESOLVED Self Reported Incident Certificate Misissuance Opened 2022-10-03 · Closed 2023-02-22 · 61% similar
D-TRUST: CRL not DER-encoded

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action