IdenTrust: Invalid OrganizationIdentifier in S/MIME certificates
IdenTrust reported an incident discovered during pre-deployment testing of a new PKI linting tool on May 29, 2024. The issue was that its internal organizationIdentifier validation logic for GOVUS entities was incorrect, which allowed issuance of S/MIME certificates with the wrong organization validation scheme. IdenTrust stated it found only one active certificate with the issue and revoked that certificate within 24 hours. It also deployed a new S/MIME linting tool on June 1, 2024, and updated its validation scheme logic and software change control process as of June 1, 2024. In response to Mozilla’s question about a planned alerting change, IdenTrust clarified that a code fix deployed on June 1, 2024 changed how organizational identifiers are handled and no longer accepts the 'GOV' scheme for organizational IDs containing a hyphen followed by an 8-digit number. The bug is resolved as FIXED.
- During testing of a new PKI linting tool, IdenTrust discovered incorrect organizationIdentifier validation logic for GOVUS entities that could allow issuance of S/MIME certificates with the wrong validation scheme.
- IdenTrust revoked the single active affected S/MIME certificate.
- IdenTrust deployed a new S/MIME linting tool and corrected the organizationIdentifier validation logic in its software change control process.
- IdenTrust Services, LLC — IdenTrust disclosed the incident, described the root cause (incorrect GOVUS organizationIdentifier validation), reported finding one active affected certificate, and stated it was revoked within 24 hours; it also provided actions taken and prevention items.
- Community commenter — Mozilla asked IdenTrust to ensure the incident report timeline includes relevant events leading up to and during the incident, including when the certificate was issued.
- IdenTrust Services, LLC — IdenTrust provided an updated timeline including a September 30, 2023 deployment and an October 19, 2023 issuance of the affected S/MIME certificate, and explained the correct scheme should have been NTR.
- IdenTrust Services, LLC — IdenTrust stated the organizationIdentifier validation scheme logic was corrected and incorporated into its software change control process as of June 1, 2024, with no remaining outstanding items.
- Mozilla representative — Mozilla asked what the June 1, 2024 planned alerting update meant regarding invalid registration schemes.
- IdenTrust Services, LLC — IdenTrust clarified that on June 1, 2024 a code fix changed organizational identifier handling and no longer accepts the 'GOV' scheme when the organizational ID contains a hyphen followed by an 8-digit number.
- Mozilla representative — Mozilla indicated intent to close the bug next week (June 17–21).