D-Trust: Non-compliance of issued root and intermediate S/MIME certificates
The bug was opened after an external party raised concerns that some D-Trust root and intermediate certificates for Germany use a potentially non-unique OrganizationIdentifier value (2.5.4.97=NTRDE-HRB74346) rather than a unique identifier (e.g., VATDE-202620438) expected for S/MIME certificate requirements. The reporter questioned whether the older roots are compliant and whether revocation of the older roots would be appropriate given their age and the existence of newer compliant roots. D-Trust responded that NTR numbers in Germany are not unique because they are assigned regionally, and stated that they are adapting products so that D-Trust’s CAs have a unique OI. D-Trust also disputed the reporter’s understanding of the scope, stating that the CAs referenced do not issue S/MIME certificates or are not subject to the S/MIME Baseline Requirements, and later clarified that the audit report included all “Issuing CAs” of their Browser integrated S/MIME Root CAs and that wording may have caused misunderstanding. D-Trust said it would work with TÜVIT to find a better solution to avoid similar misunderstandings in the future and pointed to the CA certificate, noting that S/MIME OID and “Key Usage for Email Protection” are not included. The reporter asked for explicit confirmation and remediation details, and later requested that the thread be closed; Mozilla indicated it would close unless further comments or questions were needed. The bug is currently marked RESOLVED with resolution INVALID.
- Mozilla CA Program bug 1918427 was created regarding alleged non-unique OrganizationIdentifier values in certain D-Trust root and intermediate certificates.
- D-Trust stated it was investigating the report and would respond by the end of the following week.
- D-Trust provided its investigation response and discussed how NTR numbers are used in Germany and that it is adapting to use unique OIs.
- The reporter challenged D-Trust’s scope statement by referencing an external TÜVIT audit attestation and asked how the referenced roots/intermediates are used.
- D-Trust clarified the audit report wording and said it would work with TÜVIT to avoid future misunderstandings, pointing to additional repository materials.
- The reporter asked that the thread be closed.
- Mozilla indicated it would close the bug later that week unless further questions remained.
- Mozilla representative — The reporter raised concerns that some D-Trust root/intermediate certificates use a non-unique OrganizationIdentifier (NTRDE-HRB74346) and questioned compliance with S/MIME requirements and whether older roots should be revoked.
- D-Trust — D-Trust said it was investigating and would respond by the end of next week.
- D-Trust — D-Trust stated it is aware NTR numbers are not unique in Germany, said it is adapting to use unique OIs, and argued the referenced CAs are not in scope for S/MIME BRs.
- Mozilla representative — The reporter disputed the scope claim by citing a TÜVIT S/MIME audit attestation document and asked for remediation and explicit confirmation of usage.
- D-Trust — D-Trust clarified that the audit report included all “Issuing CAs” of their Browser integrated S/MIME Root CAs, said wording may have been misinterpreted, and stated it would work with TÜVIT to improve future reporting.
- Bdr representative — The reporter asked whether the thread could be closed.
- Mozilla representative — Mozilla said it would close the bug later that week unless there were remaining comments or questions.