← A-Trust cases
Bugzilla #1972887
Self Reported Incident
Revocation Issue
A-Trust: TLS non-compliance detected during linter implementation
RESOLVED
FIXED
A-Trust
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
A-Trust identified non-compliance issues with its TLS certificates during the implementation of a linting mechanism. The CA discovered that 66 certificates were affected, with 20 still valid at the time of reporting. Issues included critical extensions not marked, invalid subject order, and missing organization IDs. A-Trust paused the issuance of new certificates and planned to revoke the non-compliant ones by June 23, 2025. The CA has since revoked all affected certificates and implemented a mandatory linting process for all TLS certificates to prevent future occurrences.
Chronology
- Non-compliance identified
- Revocation of all affected certificates
Thread Activity
- A-trust representative — Created attachment with full incident report detailing non-compliance issues.
- A-trust representative — Confirmed that all certificates reported have been revoked.
- A-trust representative — Provided a closure summary detailing the incident and remediation actions taken.
Participants
A-trust representative
Community commenter
Binaryparadox representative
DigiCert
Sectigo
HARICA
CCADB representative
External References
Similar Local Cases
IdenTrust: Test Certificates from cross-signed roots not disclosed in CT Logs
NETLOCK: Missing CDP Disclosure in CCADB
DigiCert: Misissued code signing certificates
certSIGN: certificates with delayed SCT signature
Actalis: Issuance of certificate using keys previously reported as compromised
IdenTrust: Root OCSP Signer certificate mis-issuance
DigiCert: Re-use of WHOIS validation shortly after deadline
Telia: Certificates Issued with lower case value in subject:countryName