← iTrusChina Co., Ltd. cases
Bugzilla #1927384 Certificate Misissuance

iTrusChina: Issuance of certificates using keys previously reported as compromised

RESOLVED FIXED iTrusChina Co., Ltd.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

iTrusChina was notified by Google that it may have issued certificates using private keys previously disclosed as compromised. Following this notification, iTrusChina conducted an investigation and confirmed that eight keys marked as compromised were reused to issue 41 certificates for test websites. The root cause was identified as a system bug that incorrectly set the default revocation reason to keyCompromise, compounded by staff misunderstanding of relevant requirements. All mis-issued certificates have been revoked, and iTrusChina has implemented training and system updates to prevent future occurrences. The incident report has been completed and submitted for closure.

Model: gpt-4o-mini Generated: 2026-06-13 21:13 UTC Revised: 2026-06-16 19:11 UTC Confidence: 0.85 16 comments
Chronology
  1. iTrusChina was notified by Google about potential mis-issued certificates.
  2. iTrusChina confirmed the mis-issuance and began corrective actions.
  3. iTrusChina submitted the incident report closure summary.
Thread Activity
  1. iTrusChina Co., Ltd. — iTrusChina was notified that it may have issued certificates where the Applicant’s Private Key has been previously disclosed as having been compromised.
  2. iTrusChina Co., Ltd. — iTrusChina confirmed eight keys were reused to issue test website certificates and has revoked all mis-issued certificates.
  3. iTrusChina Co., Ltd. — iTrusChina submitted the incident report closure summary detailing the incident and remediation steps.
Participants
iTrusChina Co., Ltd. HARICA Mozilla representative Sectigo
External References
Similar Local Cases
#1895006 RESOLVED Certificate Misissuance Opened 2024-05-03 · Closed 2024-08-23 · 83% similar
IdenTrust: unintended creation of a Root CA certificate
#1744827 RESOLVED Certificate Misissuance Delayed Revocation Opened 2021-12-07 · Closed 2024-03-08 · 79% similar
Entrust: SSL Certificates issued with Un-verified IP Addresses
#1889672 RESOLVED Certificate Misissuance Opened 2024-04-04 · Closed 2024-06-01 · 78% similar
Disig: Certificates with incorrect Subject attribute order
#1829746 RESOLVED Certificate Misissuance Opened 2023-04-24 · Closed 2023-06-02 · 77% similar
Sectigo: Certificate issuance delayed for more than 398 days after DCV was completed
#1936908 RESOLVED Certificate Misissuance Opened 2024-12-12 · Closed 2025-03-18 · 77% similar
DigiCert: Encoded HTML entities in attribute values
#1836694 RESOLVED Certificate Misissuance Policy Document Issue Opened 2023-06-05 · Closed 2023-09-29 · 77% similar
Hongkong Post: Invalid EV cert businessCategory
#1887096 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2024-03-22 · Closed 2024-09-06 · 77% similar
Chunghwa Telecom: Wrong Extended Key Usage setting by GTLSCA
#1883416 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2024-03-04 · Closed 2024-08-28 · 77% similar
Certigna: TLS certificates with Basic constraint non-critical

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action