← IdenTrust Services, LLC cases
Bugzilla #1900492 Incident

IdenTrust: Invalid OrganizationIdentifier in S/MIME certificates

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

IdenTrust reported an incident discovered during pre-deployment testing of a new PKI linting tool on May 29, 2024. The issue was that its internal organizationIdentifier validation logic for GOVUS entities was incorrect, which allowed issuance of S/MIME certificates with the wrong organization validation scheme. IdenTrust stated it found only one active certificate with the issue and revoked that certificate within 24 hours. It also deployed a new S/MIME linting tool on June 1, 2024, and updated its validation scheme logic and software change control process as of June 1, 2024. In response to Mozilla’s question about a planned alerting change, IdenTrust clarified that a code fix deployed on June 1, 2024 changed how organizational identifiers are handled and no longer accepts the 'GOV' scheme for organizational IDs containing a hyphen followed by an 8-digit number. The bug is resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:27 UTC Revised: 2026-06-16 19:27 UTC Confidence: 0.90 7 comments
Chronology
  1. During testing of a new PKI linting tool, IdenTrust discovered incorrect organizationIdentifier validation logic for GOVUS entities that could allow issuance of S/MIME certificates with the wrong validation scheme.
  2. IdenTrust revoked the single active affected S/MIME certificate.
  3. IdenTrust deployed a new S/MIME linting tool and corrected the organizationIdentifier validation logic in its software change control process.
Thread Activity
  1. IdenTrust Services, LLC — IdenTrust disclosed the incident, described the root cause (incorrect GOVUS organizationIdentifier validation), reported finding one active affected certificate, and stated it was revoked within 24 hours; it also provided actions taken and prevention items.
  2. Community commenter — Mozilla asked IdenTrust to ensure the incident report timeline includes relevant events leading up to and during the incident, including when the certificate was issued.
  3. IdenTrust Services, LLC — IdenTrust provided an updated timeline including a September 30, 2023 deployment and an October 19, 2023 issuance of the affected S/MIME certificate, and explained the correct scheme should have been NTR.
  4. IdenTrust Services, LLC — IdenTrust stated the organizationIdentifier validation scheme logic was corrected and incorporated into its software change control process as of June 1, 2024, with no remaining outstanding items.
  5. Mozilla representative — Mozilla asked what the June 1, 2024 planned alerting update meant regarding invalid registration schemes.
  6. IdenTrust Services, LLC — IdenTrust clarified that on June 1, 2024 a code fix changed organizational identifier handling and no longer accepts the 'GOV' scheme when the organizational ID contains a hyphen followed by an 8-digit number.
  7. Mozilla representative — Mozilla indicated intent to close the bug next week (June 17–21).
Participants
IdenTrust Services, LLC Community commenter Mozilla representative
Similar Local Cases
#1905446 RESOLVED Incident Opened 2024-06-28 · Closed 2024-12-09 · 97% similar
IdenTrust: Unauthorized OCSP response on a Timestamp certificate
#1753287 RESOLVED Incident Opened 2022-02-02 · Closed 2024-07-08 · 97% similar
IdenTrust: Validation Source for EV Certificates not Publicly Disclosed
#1838315 RESOLVED Ca Security Vulnerability Incident Opened 2023-06-13 · Closed 2023-10-12 · 96% similar
IdenTrust: Certificate with missing details flagged by OCSP Watch
#1709192 RESOLVED Incident Opened 2021-05-03 · Closed 2023-02-22 · 95% similar
IdenTrust: Unavailable CRL for IdenTrust ‘DST Root CA X3’.
#2014610 RESOLVED Self Reported Incident Incident Opened 2026-02-05 · Closed 2026-04-11 · 87% similar
IdenTrust: Root OCSP Signer certificate mis-issuance
#2016585 RESOLVED Self Reported Incident Incident Opened 2026-02-12 · Closed 2026-06-15 · 87% similar
IdenTrust: Test Certificates from cross-signed roots not disclosed in CT Logs
#2025596 RESOLVED Self Reported Incident Incident Opened 2026-03-23 · Closed 2026-05-18 · 87% similar
IdenTrust: Delay in updating a Bugzilla ticket Bug 2014610 - Next update
#1542082 RESOLVED Incident Self Reported Incident Opened 2019-04-04 · Closed 2023-02-22 · 87% similar
IdenTrust: Failure to disclose Unconstrained intermediate Within 7 Days

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action