← IdenTrust Services, LLC cases
Bugzilla #1910195 Certificate Misissuance Self Reported Incident

IdenTrust: Invalid special characters in S/MIME Certificates

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

IdenTrust disclosed an incident involving improper encoding of special characters in the Subject common name field of S/MIME certificates, which was not in line with RFC 5280 section 7.1. The issue was discovered by IdenTrust’s engineering team and affected one active and one revoked S/MIME certificate, resulting in the mis-issuance of two certificates. IdenTrust reported that it revoked the affected active certificate and also revoked the other certificate that was already revoked, and it generated a replacement certificate for the active one. IdenTrust stated it updated its configuration to stop similar mis-issuance and identified that PKILint was not properly configured for the affected customer account, which prevented linting from completing. In its final report, IdenTrust provided a timeline and root cause analysis, and listed action items including configuring PKILint to scan all S/MIME certificate accounts and implementing a process to include linting configuration during enterprise customer onboarding. IdenTrust later confirmed that it implemented the linting process for both existing and new enterprise customers and considered the issue resolved; Mozilla indicated it would close the bug on 6-Sept-2024.

Model: gpt-5.4-nano Generated: 2026-06-13 21:28 UTC Revised: 2026-06-16 19:27 UTC Confidence: 0.90 4 comments
Chronology
  1. A customer certificate was generated that later was reported as not working with the customer’s system.
  2. The affected certificate was revoked and a new certificate was generated.
  3. The active certificate was revoked and replaced.
  4. IdenTrust confirmed implementation of the linting process for existing and new enterprise customers.
Thread Activity
  1. IdenTrust Services, LLC — IdenTrust opened a preliminary incident report stating it was investigating invalid special characters in the subject of S/MIME certificates and had revoked the active certificate and updated configuration to stop mis-issuance.
  2. IdenTrust Services, LLC — IdenTrust posted a final report describing a configuration issue causing improper RFC 5280 encoding, confirming mis-issuance of two S/MIME certificates, providing a timeline and root cause analysis, and listing completed and planned action items.
  3. IdenTrust Services, LLC — IdenTrust confirmed it implemented the linting process for both existing and new enterprise customers and considered the issue resolved.
  4. Mozilla representative — Mozilla indicated it would take a look at closing the bug on Friday, 6-Sept-2024.
Participants
IdenTrust Services, LLC Mozilla representative
External References
Similar Local Cases
#1853783 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2023-09-18 · Closed 2025-03-20 · 100% similar
IdenTrust: S/MIME certificates issued in violation of New S/MIME Baseline Requirements v1.0
#1930029 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-11-08 · Closed 2025-02-19 · 100% similar
IdenTrust: Approval of TLS certificate renewal without domain validation
#2026351 RESOLVED Self Reported Incident Certificate Misissuance Opened 2026-03-25 · Closed 2026-05-18 · 100% similar
Identrust: Root CrossSign, of dedicated Roots, missing EKU
#2014609 RESOLVED Self Reported Incident Certificate Misissuance Opened 2026-02-05 · Closed 2026-04-11 · 99% similar
IdenTrust: Cross-signed root certificate mis-issuance
#1756261 RESOLVED Certificate Misissuance Opened 2022-02-18 · Closed 2023-02-22 · 99% similar
IdenTrust: EV TLS certificate with invalid Jurisdiction state for government entity
#1794047 RESOLVED Revocation Issue Self Reported Incident Opened 2022-10-06 · Closed 2023-02-22 · 98% similar
IdenTrust: Missing Revocation Reasons in CRL
#1933353 RESOLVED Self Reported Incident Opened 2024-11-25 · Closed 2025-03-21 · 97% similar
IdenTrust: Incorrect response for OCSP validation
#1500593 RESOLVED Self Reported Incident Certificate Misissuance Opened 2018-10-19 · Closed 2023-02-22 · 97% similar
IdenTrust: Internal names / failure to report

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action