← IdenTrust Services, LLC cases
Bugzilla #1919162 Certificate Misissuance

IdenTrust: TLS Certificates with outdated certificate profile

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

IdenTrust reported that it discovered seven active TLS subscriber certificates were issued using an outdated certificate profile that was no longer supported by the TLS Baseline Requirements (BR) as of 2024-09-15. The outdated profile issues included an incorrect inclusion of a userNotice in the Certificate Policies extension and Subject field attributes not arranged in the predefined relative order required by the BR. IdenTrust stated that it identified the root cause as a failure to update the certificate profile to align with the latest TLS BR that came into effect in September 2023. After discovery, IdenTrust completed revocation of the seven certificates on 2024-09-13 and later disclosed a preliminary incident report in Bugzilla on 2024-09-16. IdenTrust also revised its timeline and root cause analysis in response to Mozilla questions, and reported that it improved its standard operating procedures so that certificate profile requests require Delivery Team signoff before deployment in production. The bug was marked RESOLVED with resolution FIXED, and IdenTrust stated on 2024-10-25 that it considered the outstanding items addressed and the issue resolved.

Model: gpt-5.4-nano Generated: 2026-06-13 21:30 UTC Revised: 2026-06-16 19:27 UTC Confidence: 0.86 8 comments
Chronology
  1. IdenTrust updated TLS certificate profiles to be compliant with BR v2.0.0.
  2. A customer reported an issue retrieving a TLS certificate due to linting behavior.
  3. IdenTrust identified seven active TLS subscriber certificates issued with an outdated certificate profile.
  4. IdenTrust completed revocation of the seven certificates.
  5. IdenTrust disclosed a preliminary incident report in Bugzilla and notified roots stores.
  6. IdenTrust stated it had addressed outstanding items and considered the issue resolved.
Thread Activity
  1. IdenTrust Services, LLC — IdenTrust disclosed a preliminary incident report stating it had found seven active TLS subscriber certificates issued with an outdated certificate profile and that the certificates were revoked on 2024-09-13.
  2. IdenTrust Services, LLC — IdenTrust provided a complete incident report with root cause analysis, impact details, and action items including improved SOP requiring Delivery Team signoff for certificate profile updates.
  3. Google representative — Mozilla asked for timeline granularity updates and additional RCA detail, including questions about detection timing, the role of low usage, and how Delivery Team signoff would prevent recurrence.
  4. IdenTrust Services, LLC — IdenTrust revised the timeline and root cause analysis in response to Mozilla’s questions, including updated UTC timestamps and details about the investigation and SOP changes.
  5. Google representative — Mozilla asked further follow-up questions about issuance remaining active, why misissued certificates were discovered later, and Delivery Team roles and processes.
  6. IdenTrust Services, LLC — IdenTrust clarified that issuance remained active but linter functionality effectively prevented customers from issuing certificates, and described investigation steps and Delivery Team responsibilities.
  7. IdenTrust Services, LLC — IdenTrust stated it believed all outstanding items were addressed and considered the issue resolved.
  8. Mozilla representative — Mozilla indicated it would pull the case back up on 1-Nov-2024 and consider closing if there were no further questions or issues.
Participants
IdenTrust Services, LLC Google representative Mozilla representative
Similar Local Cases
#1850807 RESOLVED Certificate Misissuance Opened 2023-08-30 · Closed 2023-09-29 · 87% similar
IdenTrust: basicConstraints not flagged "Critical" Per Certification Practices Statement
#1897569 RESOLVED Certificate Misissuance Opened 2024-05-17 · Closed 2024-08-23 · 87% similar
IdenTrust: TLS ICA with User Notice in Policy Qualifier
#1635279 RESOLVED Certificate Misissuance Opened 2020-05-04 · Closed 2023-02-22 · 87% similar
IdenTrust: Incorrect Subject Details for HydrantId
#1669594 RESOLVED Certificate Misissuance Opened 2020-10-06 · Closed 2023-02-22 · 87% similar
IdenTrust: Issuance of Subordinate CA’s Without EKU
#1796715 RESOLVED Certificate Misissuance Opened 2022-10-20 · Closed 2023-02-22 · 87% similar
IdenTrust: Mis-Issued EV Code Signing Certificate
#1861782 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-10-28 · Closed 2024-01-04 · 85% similar
IdenTrust: S/MIME certificates with Invalid document Identification Scheme
#1826713 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-04-06 · Closed 2023-07-20 · 76% similar
Actalis: Certificates issued with validity period greater than 398 days
#1782356 RESOLVED Certificate Misissuance Opened 2022-07-30 · Closed 2023-02-22 · 70% similar
Sectigo: Misspelled city name in localityName field

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action