iTrusChina: lacking 2018 KGC and GAP period audit reports
iTrusChina filed this incident report after being notified by Google that it lacked the 2018 Key Generation Ceremony (KGC) report and the GAP period audit reports covering July 31, 2018 to October 7, 2018. iTrusChina stated this was considered a violation of TLS BR Sections 6.1.1.1 and 8.1, including the requirement for qualified auditor reporting and unbroken sequence of audit periods. iTrusChina said the issue was first discovered by Chris Clements from the Chrome Root Program Team on April 12, 2024, and that after consulting with the Chrome Root Program Team and its auditor, it began supplementing the missing KGC and GAP period audit reports. The supplemental KGC report was completed at the end of July 2024, and the GAP period audit reports were completed at the end of September 2024, with documents disclosed on Bug 1759965. iTrusChina also stated that no subscriber certificates were impacted because it did not issue certificates until December 2018, which was covered by later consecutive audit reports. The bug was resolved as FIXED, and iTrusChina requested closure after stating all action items were completed as described.
- iTrusChina conducted KGC for its two roots witnessed by a Qualified Auditor, without a separate KGC report at that time.
- The period covered by iTrusChina’s first point-in-time audit report began.
- iTrusChina was notified that it lacked the 2018 KGC and GAP period audit reports.
- The supplemental 2018 KGC report was completed.
- The supplemental 2018 GAP period audit reports were completed.
- iTrusChina received confirmation from Google that the reports met expectations and filed the incident report for community transparency.
- iTrusChina requested closure and Mozilla indicated it would close the bug later that week.
- iTrusChina Co., Ltd. — Reported that Google notified iTrusChina it lacked the 2018 KGC report and GAP period audit reports, described as violations of TLS BR Sections 6.1.1.1 and 8.1.
- Community commenter — Noted that the root generation report attachment referenced in Bug 1759965 did not include the management assertion in the uploaded PDF.
- iTrusChina Co., Ltd. — Responded that new 2018 KGC reports including the management assertion were unloaded on Bug 1759965.
- Community commenter — Raised concerns after reviewing historical information, questioning security risks based on the timing of KGC versus HSM FIPS certification claims.
- iTrusChina Co., Ltd. — Responded that the incident focus was on missing audit reports and stated the HSM issue was fully disclosed in the 2021 root inclusion discussion, with current HSMs described as fully FIPS-compliant.
- iTrusChina Co., Ltd. — Provided an incident report closure summary stating additional audits were completed, unqualified 2018 KGC and audit reports were provided, staff training was conducted, and all action items were completed; requested closure.
- Mozilla representative — Indicated the bug would be closed later that week unless there were questions or issues to resolve.