← IdenTrust Services, LLC cases
Bugzilla #1930029 Self Reported Incident Certificate Misissuance

IdenTrust: Approval of TLS certificate renewal without domain validation

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

IdenTrust Services, LLC identified a mis-issuance of a TLS OV certificate during their internal quality assurance process on November 5, 2024. The certificate was issued without completing the necessary domain revalidation, violating TLS BR Section 3.2.2.4. The CA revoked the mis-issued certificate on November 6, 2024, and reported the incident to Mozilla. A complete incident report was provided, detailing the root cause and corrective measures, including retraining of staff and plans to implement technical controls to prevent future occurrences. The CA has committed to deploying these fixes by February 2025.

Model: gpt-4o-mini Generated: 2026-06-13 21:30 UTC Revised: 2026-06-16 19:28 UTC Confidence: 0.85 11 comments
Chronology
  1. IdenTrust identified the mis-issuance of a TLS OV certificate.
  2. The mis-issued certificate was revoked.
  3. Technical controls were added to the older API version.
Thread Activity
  1. IdenTrust Services, LLC — IdenTrust reported the mis-issuance and revocation of a TLS certificate.
  2. IdenTrust Services, LLC — IdenTrust provided a complete incident report detailing the mis-issuance.
  3. IdenTrust Services, LLC — IdenTrust outlined additional measures taken to prevent recurrence.
  4. IdenTrust Services, LLC — IdenTrust confirmed they are on track to deploy the promised fix.
  5. IdenTrust Services, LLC — IdenTrust reported completion of all action items related to the incident.
  6. Mozilla representative — Mozilla indicated plans to close the case.
Participants
IdenTrust Services, LLC Mozilla representative
External References
Similar Local Cases
#1853783 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2023-09-18 · Closed 2025-03-20 · 100% similar
IdenTrust: S/MIME certificates issued in violation of New S/MIME Baseline Requirements v1.0
#1910195 RESOLVED Certificate Misissuance Self Reported Incident Opened 2024-07-26 · Closed 2024-09-06 · 100% similar
IdenTrust: Invalid special characters in S/MIME Certificates
#2014609 RESOLVED Self Reported Incident Certificate Misissuance Opened 2026-02-05 · Closed 2026-04-11 · 100% similar
IdenTrust: Cross-signed root certificate mis-issuance
#1500593 RESOLVED Self Reported Incident Certificate Misissuance Opened 2018-10-19 · Closed 2023-02-22 · 98% similar
IdenTrust: Internal names / failure to report
#1895006 RESOLVED Certificate Misissuance Opened 2024-05-03 · Closed 2024-08-23 · 97% similar
IdenTrust: unintended creation of a Root CA certificate
#1933353 RESOLVED Self Reported Incident Opened 2024-11-25 · Closed 2025-03-21 · 97% similar
IdenTrust: Incorrect response for OCSP validation
#2026351 RESOLVED Self Reported Incident Certificate Misissuance Opened 2026-03-25 · Closed 2026-05-18 · 97% similar
Identrust: Root CrossSign, of dedicated Roots, missing EKU
#1718552 RESOLVED Certificate Misissuance Opened 2021-06-28 · Closed 2023-02-22 · 97% similar
IdenTrust: Certificates with Invalid values for stateOrProvinceName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action