← IdenTrust Services, LLC cases
Bugzilla #1895006 Certificate Misissuance

IdenTrust: unintended creation of a Root CA certificate

RESOLVED FIXED IdenTrust Services, LLC
AI Summary

On April 30, 2024, during a key ceremony intended for a Subordinate Certification Authority (CA), an incorrect command led to the unintended creation of a self-signed Root CA certificate. This certificate did not meet the Server Certificate Baseline Requirements and was disclosed in the Common CA Database (CCADB). IdenTrust has since revoked the malformed certificate and is committed to improving their processes to prevent similar incidents in the future. A detailed incident report is expected by May 17, 2024.

Model: gpt-4o-mini Generated: 2026-06-13 21:26 UTC Confidence: 0.90
Chronology
  1. Unintended creation of a self-signed Root CA certificate during a key ceremony.
  2. Preliminary incident report disclosed.
  3. Revocation of the malformed self-signed Root CA certificate.
  4. Full incident report expected.
Participants
roots@identrust.com agwa-bugs@mm.beanwood.com rob@sectigo.com amir@aaomidi.com dzacharo@harica.gr martijn.katerbarg@sectigo.com corey.bonnell@digicert.com mathew.hodson@gmail.com bwilson@mozilla.com
External References
Similar Local Cases
#1796715 RESOLVED Certificate Misissuance Opened 2022-10-20 · Closed 2023-02-22 · 73% similar
IdenTrust: Mis-Issued EV Code Signing Certificate
#2016722 RESOLVED Certificate Misissuance Opened 2026-02-13 · Closed 2026-03-17 · 64% similar
PostSignum: Mis-issued certificate
#1838371 RESOLVED Certificate Misissuance Opened 2023-06-14 · Closed 2024-01-19 · 63% similar
CFCA: certificate with an incorrect OrganizationName
#1871113 RESOLVED Certificate Misissuance Opened 2023-12-20 · Closed 2024-05-15 · 63% similar
SSL.com: Issuance of one Sponsored-Validated S/MIME certificate with organization information in givenName and surName of the subjectDN
#1927384 RESOLVED Certificate Misissuance Opened 2024-10-28 · Closed 2025-01-29 · 62% similar
iTrusChina: Issuance of certificates using keys previously reported as compromised
#2014609 RESOLVED Certificate Misissuance Opened 2026-02-05 · Closed 2026-04-11 · 58% similar
IdenTrust: Cross-signed root certificate mis-issuance
#1888060 RESOLVED Certificate Misissuance Opened 2024-03-27 · Closed 2025-03-05 · 58% similar
GDCA: Issuance of SSL/TLS certificates with Non-critical Basic Constraints
#1724520 RESOLVED Certificate Misissuance Opened 2021-08-06 · Closed 2023-02-22 · 56% similar
SSL.com: Incorrect Domain Validation for 1 TLS certificate with FQDN having "www." string within domain labels

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action