iTrusChina: Issuance of certificates using keys previously reported as compromised
iTrusChina was notified by Google that it may have issued certificates using private keys previously disclosed as compromised. Following this notification, iTrusChina conducted an investigation and confirmed that eight keys marked as compromised were reused to issue 41 certificates for test websites. The root cause was identified as a system bug that incorrectly set the default revocation reason to keyCompromise, compounded by staff misunderstanding of relevant requirements. All mis-issued certificates have been revoked, and iTrusChina has implemented training and system updates to prevent future occurrences. The incident report has been completed and submitted for closure.
- iTrusChina was notified by Google about potential mis-issued certificates.
- iTrusChina confirmed the mis-issuance and began corrective actions.
- iTrusChina submitted the incident report closure summary.
- iTrusChina Co., Ltd. — iTrusChina was notified that it may have issued certificates where the Applicant’s Private Key has been previously disclosed as having been compromised.
- iTrusChina Co., Ltd. — iTrusChina confirmed eight keys were reused to issue test website certificates and has revoked all mis-issued certificates.
- iTrusChina Co., Ltd. — iTrusChina submitted the incident report closure summary detailing the incident and remediation steps.