← IdenTrust Services, LLC cases
Bugzilla #1900492 Certificate Problem Report

IdenTrust: Invalid OrganizationIdentifier in S/MIME certificates

RESOLVED FIXED IdenTrust Services, LLC
AI Summary

IdenTrust Services, LLC identified an issue with the organizationIdentifier validation for S/MIME certificates during testing of a new PKI linting tool. The internal validation logic erroneously allowed the issuance of a certificate with an invalid organization validation scheme. Only one certificate was affected, which was promptly revoked within 24 hours of discovery. The root cause was traced to a lack of checks in the application for GOVUS entities, and corrective measures, including the deployment of the linting tool and updates to the validation logic, have been implemented.

Model: gpt-4o-mini Generated: 2026-06-13 21:27 UTC Confidence: 0.95
Chronology
  1. Deploy Organization Validation Scheme per the S/MIME BR
  2. Issued S/MIME certificate with invalid registration scheme identifier
  3. QA operator discovered validation issue during testing
  4. Revoked the affected certificate
  5. Deployed the new S/MIME linting tool
Participants
IdenTrust Mathew Hodson Ben Wilson
External References
Similar Local Cases
#1749089 RESOLVED Certificate Problem Report Opened 2022-01-08 · Closed 2023-02-22 · 68% similar
IdenTrust: OCSP Signer Certificate Missing No-Check Extension
#1933353 RESOLVED Certificate Problem Report Opened 2024-11-25 · Closed 2025-03-21 · 67% similar
IdenTrust: Incorrect response for OCSP validation
#1756850 RESOLVED Certificate Problem Report Opened 2022-02-23 · Closed 2023-02-22 · 67% similar
IdenTrust: EV TLS certificate with wrong jurisdiction state for private organization
#1897569 RESOLVED Certificate Problem Report Opened 2024-05-17 · Closed 2024-08-23 · 65% similar
IdenTrust: TLS ICA with User Notice in Policy Qualifier
#1718552 RESOLVED Certificate Problem Report Opened 2021-06-28 · Closed 2023-02-22 · 62% similar
IdenTrust: Certificates with Invalid values for stateOrProvinceName
#1526099 RESOLVED Certificate Problem Report Opened 2019-02-07 · Closed 2023-02-22 · 61% similar
IdenTrust: Discrepancy in values of address fields within CN of SSL Certificates
#1853783 RESOLVED Certificate Problem Report Opened 2023-09-18 · Closed 2025-03-20 · 59% similar
IdenTrust: S/MIME certificates issued in violation of New S/MIME Baseline Requirements v1.0
#1861783 RESOLVED Certificate Problem Report Opened 2023-10-28 · Closed 2024-01-04 · 59% similar
IdenTrust: S/MIME Certificates issued without CAB Forum OID

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action