← IdenTrust Services, LLC cases
Bugzilla #1897569 Certificate Misissuance

IdenTrust: TLS ICA issued with disallowed “User Notice” policy qualifier; revoked and linter updated

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

IdenTrust reported that an intermediate CA certificate (ICA) was issued with the “User Notice” policy qualifier within the certificatePolicies extension, which it stated is no longer permitted by the CA/Browser Forum Server Baseline Requirements as of September 15, 2023. IdenTrust said the issuance was not BR compliant and that it came to their attention on May 9, 2024, via comment #12 on another IdenTrust Bugzilla bug (1895006). IdenTrust stated that the ICA was promptly revoked and that it established a process to ensure the Linter tool is updated with the most current validations. In its root cause analysis, IdenTrust said the Linter tool used to validate certificate issuance failed to detect the discrepancy because the version in use had not been internally updated with the latest validation checks. IdenTrust also discussed delaying the linter update from June 30, 2024, until July 20, 2024, and then stated that it successfully deployed the updated linter on July 20, 2024 and improved ongoing processes for keeping the linter tool up to date. The thread indicates no further remediation actions were pending as of August 20, 2024, and Mozilla indicated it would close the bug on August 23, 2024; the bug is resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:27 UTC Revised: 2026-06-16 19:27 UTC Confidence: 0.86 9 comments
Chronology
  1. PKI operator created the ICA in a pre-production environment and it passed Linter validation for production issuance.
  2. PKI operations began key ceremony to create the ICA in production, including creation of a malformed self-signed Root CA and then the expected ICA.
  3. The new ICA was uploaded into CCADB.
  4. IdenTrust became aware of the issue and started the process to revoke the ICA.
  5. IdenTrust revoked the ICA.
  6. IdenTrust deployed the updated Linter during the scheduled change control.
  7. IdenTrust stated there were no further remediation actions pending.
Thread Activity
  1. IdenTrust Services, LLC — IdenTrust opened the incident report stating an ICA was issued with a disallowed “User Notice” policy qualifier, that it was promptly revoked, and that the Linter tool needed updating; it also provided a timeline and action item to update the Linter tool.
  2. Community commenter — A commenter asked for missing details about when IdenTrust became aware of the BR change and what actions were taken after the ballot passed, and why the ICA profile was not updated.
  3. IdenTrust Services, LLC — IdenTrust responded that it was aware of proposed profile updates since February 2023 and that ballot SC-62v2 was adopted effective September 15, 2023; it described its BR compliance process and stated the ICA profile update failed due to human oversight and a failed technical control (missing updated linter).
  4. IdenTrust Services, LLC — IdenTrust stated it would delay updating the linter tool from June 30, 2024 to July 20, 2024 and explained its rationale.
  5. IdenTrust Services, LLC — IdenTrust reported that it successfully deployed the updated linter on July 20, 2024.
  6. IdenTrust Services, LLC — IdenTrust reported that it improved and implemented ongoing processes for keeping the linter tool up to date.
  7. IdenTrust Services, LLC — IdenTrust stated there were no further remediation actions pending for the issue.
  8. Mozilla representative — Mozilla indicated it would look at closing the bug on Friday, 23-Aug-2024.
Participants
IdenTrust Services, LLC Community commenter Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1850807 RESOLVED Certificate Misissuance Opened 2023-08-30 · Closed 2023-09-29 · 97% similar
IdenTrust: basicConstraints not flagged "Critical" Per Certification Practices Statement
#1635279 RESOLVED Certificate Misissuance Opened 2020-05-04 · Closed 2023-02-22 · 97% similar
IdenTrust: Incorrect Subject Details for HydrantId
#1796715 RESOLVED Certificate Misissuance Opened 2022-10-20 · Closed 2023-02-22 · 97% similar
IdenTrust: Mis-Issued EV Code Signing Certificate
#1669594 RESOLVED Certificate Misissuance Opened 2020-10-06 · Closed 2023-02-22 · 96% similar
IdenTrust: Issuance of Subordinate CA’s Without EKU
#1861782 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-10-28 · Closed 2024-01-04 · 95% similar
IdenTrust: S/MIME certificates with Invalid document Identification Scheme
#1919162 RESOLVED Certificate Misissuance Opened 2024-09-16 · Closed 2024-12-09 · 87% similar
IdenTrust: TLS Certificates with outdated certificate profile
#1756850 RESOLVED Certificate Misissuance Opened 2022-02-23 · Closed 2023-02-22 · 85% similar
IdenTrust: EV TLS certificate with wrong jurisdiction state for private organization
#1895006 RESOLVED Certificate Misissuance Opened 2024-05-03 · Closed 2024-08-23 · 83% similar
IdenTrust: unintended creation of a Root CA certificate

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action