← iTrusChina Co., Ltd. cases
Bugzilla #1923279 Audit Finding

iTrusChina: lacking 2018 KGC and GAP period audit reports

RESOLVED FIXED iTrusChina Co., Ltd.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

iTrusChina filed this incident report after being notified by Google that it lacked the 2018 Key Generation Ceremony (KGC) report and the GAP period audit reports covering July 31, 2018 to October 7, 2018. iTrusChina stated this was considered a violation of TLS BR Sections 6.1.1.1 and 8.1, including the requirement for qualified auditor reporting and unbroken sequence of audit periods. iTrusChina said the issue was first discovered by Chris Clements from the Chrome Root Program Team on April 12, 2024, and that after consulting with the Chrome Root Program Team and its auditor, it began supplementing the missing KGC and GAP period audit reports. The supplemental KGC report was completed at the end of July 2024, and the GAP period audit reports were completed at the end of September 2024, with documents disclosed on Bug 1759965. iTrusChina also stated that no subscriber certificates were impacted because it did not issue certificates until December 2018, which was covered by later consecutive audit reports. The bug was resolved as FIXED, and iTrusChina requested closure after stating all action items were completed as described.

Model: gpt-5.4-nano Generated: 2026-06-13 21:12 UTC Revised: 2026-06-16 19:11 UTC Confidence: 0.86 8 comments
Chronology
  1. iTrusChina conducted KGC for its two roots witnessed by a Qualified Auditor, without a separate KGC report at that time.
  2. The period covered by iTrusChina’s first point-in-time audit report began.
  3. iTrusChina was notified that it lacked the 2018 KGC and GAP period audit reports.
  4. The supplemental 2018 KGC report was completed.
  5. The supplemental 2018 GAP period audit reports were completed.
  6. iTrusChina received confirmation from Google that the reports met expectations and filed the incident report for community transparency.
  7. iTrusChina requested closure and Mozilla indicated it would close the bug later that week.
Thread Activity
  1. iTrusChina Co., Ltd. — Reported that Google notified iTrusChina it lacked the 2018 KGC report and GAP period audit reports, described as violations of TLS BR Sections 6.1.1.1 and 8.1.
  2. Community commenter — Noted that the root generation report attachment referenced in Bug 1759965 did not include the management assertion in the uploaded PDF.
  3. iTrusChina Co., Ltd. — Responded that new 2018 KGC reports including the management assertion were unloaded on Bug 1759965.
  4. Community commenter — Raised concerns after reviewing historical information, questioning security risks based on the timing of KGC versus HSM FIPS certification claims.
  5. iTrusChina Co., Ltd. — Responded that the incident focus was on missing audit reports and stated the HSM issue was fully disclosed in the 2021 root inclusion discussion, with current HSMs described as fully FIPS-compliant.
  6. iTrusChina Co., Ltd. — Provided an incident report closure summary stating additional audits were completed, unqualified 2018 KGC and audit reports were provided, staff training was conducted, and all action items were completed; requested closure.
  7. Mozilla representative — Indicated the bug would be closed later that week unless there were questions or issues to resolve.
Participants
iTrusChina Co., Ltd. Community commenter Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1650910 RESOLVED Self Reported Incident Audit Finding Revocation Issue Opened 2020-07-06 · Closed 2023-02-22 · 75% similar
DigiCert: Inconsistent EV audits
#1695938 RESOLVED Ca Documents Audit Finding Opened 2021-03-02 · Closed 2024-06-30 · 74% similar
SECOM: FUJIFILM intermediate CA Certificate not listed in audit statement
#2008803 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-06 · Closed 2026-02-12 · 69% similar
Chunghwa Telecom: Findings in 2025 WebTrust Audit - GTLSCA Audit Incident Report #4 - Missing evaluation for third parties
#1917046 RESOLVED Ca Documents Audit Finding Opened 2024-09-05 · Closed 2025-04-18 · 68% similar
NETLOCK: Findings in 2024 Audit
#1906028 RESOLVED Self Reported Incident Audit Finding Opened 2024-07-03 · Closed 2024-08-15 · 67% similar
Microsoft PKI Services: Vulnerability Management Exception Tracking
#1738421 RESOLVED Self Reported Incident Audit Finding Opened 2021-10-29 · Closed 2023-02-22 · 67% similar
Izenpe: CRL and ARL exceed validity period value by one second
#2008788 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-06 · Closed 2026-02-11 · 67% similar
Chunghwa Telecom: Findings in 2025 WebTrust Audit - GTLSCA Audit Incident Report #2 - Domain validation records without the TLS BR version
#1713668 RESOLVED Audit Finding Opened 2021-05-31 · Closed 2023-02-22 · 67% similar
Amazon Trust Services: ALV Errors

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action