← D-TRUST cases
Bugzilla #1918427 Ca Certificate Compliance Incident Closure Request

D-Trust: Non-compliance of issued root and intermediate S/MIME certificates

RESOLVED INVALID D-TRUST
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The bug was opened after an external party raised concerns that some D-Trust root and intermediate certificates for Germany use a potentially non-unique OrganizationIdentifier value (2.5.4.97=NTRDE-HRB74346) rather than a unique identifier (e.g., VATDE-202620438) expected for S/MIME certificate requirements. The reporter questioned whether the older roots are compliant and whether revocation of the older roots would be appropriate given their age and the existence of newer compliant roots. D-Trust responded that NTR numbers in Germany are not unique because they are assigned regionally, and stated that they are adapting products so that D-Trust’s CAs have a unique OI. D-Trust also disputed the reporter’s understanding of the scope, stating that the CAs referenced do not issue S/MIME certificates or are not subject to the S/MIME Baseline Requirements, and later clarified that the audit report included all “Issuing CAs” of their Browser integrated S/MIME Root CAs and that wording may have caused misunderstanding. D-Trust said it would work with TÜVIT to find a better solution to avoid similar misunderstandings in the future and pointed to the CA certificate, noting that S/MIME OID and “Key Usage for Email Protection” are not included. The reporter asked for explicit confirmation and remediation details, and later requested that the thread be closed; Mozilla indicated it would close unless further comments or questions were needed. The bug is currently marked RESOLVED with resolution INVALID.

Model: gpt-5.4-nano Generated: 2026-06-13 21:31 UTC Revised: 2026-06-16 18:46 UTC Confidence: 0.86 7 comments
Chronology
  1. Mozilla CA Program bug 1918427 was created regarding alleged non-unique OrganizationIdentifier values in certain D-Trust root and intermediate certificates.
  2. D-Trust stated it was investigating the report and would respond by the end of the following week.
  3. D-Trust provided its investigation response and discussed how NTR numbers are used in Germany and that it is adapting to use unique OIs.
  4. The reporter challenged D-Trust’s scope statement by referencing an external TÜVIT audit attestation and asked how the referenced roots/intermediates are used.
  5. D-Trust clarified the audit report wording and said it would work with TÜVIT to avoid future misunderstandings, pointing to additional repository materials.
  6. The reporter asked that the thread be closed.
  7. Mozilla indicated it would close the bug later that week unless further questions remained.
Thread Activity
  1. Mozilla representative — The reporter raised concerns that some D-Trust root/intermediate certificates use a non-unique OrganizationIdentifier (NTRDE-HRB74346) and questioned compliance with S/MIME requirements and whether older roots should be revoked.
  2. D-Trust — D-Trust said it was investigating and would respond by the end of next week.
  3. D-Trust — D-Trust stated it is aware NTR numbers are not unique in Germany, said it is adapting to use unique OIs, and argued the referenced CAs are not in scope for S/MIME BRs.
  4. Mozilla representative — The reporter disputed the scope claim by citing a TÜVIT S/MIME audit attestation document and asked for remediation and explicit confirmation of usage.
  5. D-Trust — D-Trust clarified that the audit report included all “Issuing CAs” of their Browser integrated S/MIME Root CAs, said wording may have been misinterpreted, and stated it would work with TÜVIT to improve future reporting.
  6. Bdr representative — The reporter asked whether the thread could be closed.
  7. Mozilla representative — Mozilla said it would close the bug later that week unless there were remaining comments or questions.
Participants
Mozilla representative D-Trust Bdr representative
Similar Local Cases
#1939809 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-01-03 · Closed 2026-06-12 · 94% similar
D-Trust: QCStatement with http link of PKI Disclosure Statements
#1924385 RESOLVED Ca Certificate Compliance Revocation Issue Closure Request Opened 2024-10-13 · Closed 2025-07-16 · 92% similar
D-Trust: Missed Revocation of TLS certificates affected by Bugzilla 1884714
#1691117 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2021-02-05 · Closed 2023-02-22 · 86% similar
D-TRUST: Certificate with RSA key where modulus is not divisible by 8
#1682270 RESOLVED Ca Certificate Compliance Incident Closure Request Opened 2020-12-14 · Closed 2026-06-12 · 84% similar
D-TRUST: Private Key Disclosed by Customer as Part of CSR
#2023458 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-03-15 · Closed 2026-06-12 · 83% similar
D-Trust: TLS Precertificates Exceeding the Maximum Validity Period Allowed by the TLS Baseline Requirements
#2056223 ASSIGNED Ca Certificate Compliance Incident Externally Reported Incident Policy Document Issue Opened 2026-07-20 Still Open · 80% similar
D-Trust OCSP Responder Certificates Include CA/B Forum DV Policy OID
#2049237 ASSIGNED Ca Certificate Compliance Incident Externally Reported Incident Revocation Issue Opened 2026-06-22 Still Open · 77% similar
HARICA: Continued issuance and refusal to revoke TLS certificates for EU-sanctioned blocked entities (Sberbank, VTB, KAMAZ, ANO Dialog)
#1647468 RESOLVED Ca Certificate Compliance Opened 2020-06-22 · Closed 2023-02-22 · 74% similar
D-TRUST: Wrong key usage (Key Encipherment)

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action