IdenTrust: unintended creation of a Root CA certificate
On April 30, 2024, during a key ceremony, IdenTrust inadvertently created a self-signed Root CA certificate instead of the intended Subordinate CA due to a command error. This new certificate did not comply with the Server Certificate Baseline Requirements. IdenTrust disclosed the incident in the Common CA Database (CCADB) and requested its placement on the OneCRL. The malformed certificate was revoked, and a full incident report detailing the root cause and corrective actions is expected by May 17, 2024. IdenTrust has since implemented changes to their certificate creation processes to prevent similar issues in the future.
- IdenTrust inadvertently created a self-signed Root CA certificate during a key ceremony.
- IdenTrust disclosed the incident in the CCADB.
- The malformed Root CA certificate was revoked.
- IdenTrust is expected to submit a full incident report.
- IdenTrust Services, LLC — An unintended event occurred during a key ceremony, resulting in the creation of a new self-signed Root CA certificate.
- Community commenter — Concerns were raised about the implications of the incident and the need for a detailed explanation.
- IdenTrust Services, LLC — IdenTrust confirmed the misissuance of the subordinate CA certificate and stated it has been revoked.
- IdenTrust Services, LLC — A detailed incident report was promised to be submitted by May 17, 2024.