← IdenTrust Services, LLC cases
Bugzilla #1895006 Certificate Misissuance

IdenTrust: unintended creation of a Root CA certificate

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

On April 30, 2024, during a key ceremony, IdenTrust inadvertently created a self-signed Root CA certificate instead of the intended Subordinate CA due to a command error. This new certificate did not comply with the Server Certificate Baseline Requirements. IdenTrust disclosed the incident in the Common CA Database (CCADB) and requested its placement on the OneCRL. The malformed certificate was revoked, and a full incident report detailing the root cause and corrective actions is expected by May 17, 2024. IdenTrust has since implemented changes to their certificate creation processes to prevent similar issues in the future.

Model: gpt-4o-mini Generated: 2026-06-13 21:26 UTC Revised: 2026-06-16 19:26 UTC Confidence: 0.85 27 comments
Chronology
  1. IdenTrust inadvertently created a self-signed Root CA certificate during a key ceremony.
  2. IdenTrust disclosed the incident in the CCADB.
  3. The malformed Root CA certificate was revoked.
  4. IdenTrust is expected to submit a full incident report.
Thread Activity
  1. IdenTrust Services, LLC — An unintended event occurred during a key ceremony, resulting in the creation of a new self-signed Root CA certificate.
  2. Community commenter — Concerns were raised about the implications of the incident and the need for a detailed explanation.
  3. IdenTrust Services, LLC — IdenTrust confirmed the misissuance of the subordinate CA certificate and stated it has been revoked.
  4. IdenTrust Services, LLC — A detailed incident report was promised to be submitted by May 17, 2024.
Participants
IdenTrust Services, LLC Mm representative Sectigo Community commenter HARICA DigiCert Mozilla representative
External References
Similar Local Cases
#1756850 RESOLVED Certificate Misissuance Opened 2022-02-23 · Closed 2023-02-22 · 100% similar
IdenTrust: EV TLS certificate with wrong jurisdiction state for private organization
#1930029 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-11-08 · Closed 2025-02-19 · 97% similar
IdenTrust: Approval of TLS certificate renewal without domain validation
#1718552 RESOLVED Certificate Misissuance Opened 2021-06-28 · Closed 2023-02-22 · 97% similar
IdenTrust: Certificates with Invalid values for stateOrProvinceName
#1910195 RESOLVED Certificate Misissuance Self Reported Incident Opened 2024-07-26 · Closed 2024-09-06 · 95% similar
IdenTrust: Invalid special characters in S/MIME Certificates
#1853783 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2023-09-18 · Closed 2025-03-20 · 94% similar
IdenTrust: S/MIME certificates issued in violation of New S/MIME Baseline Requirements v1.0
#1663080 RESOLVED Certificate Misissuance Opened 2020-09-03 · Closed 2023-02-22 · 94% similar
IdenTrust: Issuance of certificates greater than 398 days
#1756261 RESOLVED Certificate Misissuance Opened 2022-02-18 · Closed 2023-02-22 · 94% similar
IdenTrust: EV TLS certificate with invalid Jurisdiction state for government entity
#1831004 RESOLVED Certificate Misissuance Opened 2023-05-02 · Closed 2024-05-09 · 94% similar
IdenTrust: duplicate Certificate in error flagged by OCSP Watch

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action