IdenTrust: Approval of TLS certificate renewal without domain validation
IdenTrust Services, LLC identified a mis-issuance of a TLS OV certificate during their internal quality assurance process on November 5, 2024. The certificate was issued without completing the necessary domain revalidation, violating TLS BR Section 3.2.2.4. The CA revoked the mis-issued certificate on November 6, 2024, and reported the incident to Mozilla. A complete incident report was provided, detailing the root cause and corrective measures, including retraining of staff and plans to implement technical controls to prevent future occurrences. The CA has committed to deploying these fixes by February 2025.
- IdenTrust identified the mis-issuance of a TLS OV certificate.
- The mis-issued certificate was revoked.
- Technical controls were added to the older API version.
- IdenTrust Services, LLC — IdenTrust reported the mis-issuance and revocation of a TLS certificate.
- IdenTrust Services, LLC — IdenTrust provided a complete incident report detailing the mis-issuance.
- IdenTrust Services, LLC — IdenTrust outlined additional measures taken to prevent recurrence.
- IdenTrust Services, LLC — IdenTrust confirmed they are on track to deploy the promised fix.
- IdenTrust Services, LLC — IdenTrust reported completion of all action items related to the incident.
- Mozilla representative — Mozilla indicated plans to close the case.