← A-Trust cases
Bugzilla #1972887 Self Reported Incident Revocation Issue

A-Trust: TLS non-compliance detected during linter implementation

RESOLVED FIXED A-Trust
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

A-Trust identified non-compliance issues with its TLS certificates during the implementation of a linting mechanism. The CA discovered that 66 certificates were affected, with 20 still valid at the time of reporting. Issues included critical extensions not marked, invalid subject order, and missing organization IDs. A-Trust paused the issuance of new certificates and planned to revoke the non-compliant ones by June 23, 2025. The CA has since revoked all affected certificates and implemented a mandatory linting process for all TLS certificates to prevent future occurrences.

Model: gpt-4o-mini Generated: 2026-06-13 10:40 UTC Revised: 2026-06-16 17:58 UTC Confidence: 0.85 18 comments
Chronology
  1. Non-compliance identified
  2. Revocation of all affected certificates
Thread Activity
  1. A-trust representative — Created attachment with full incident report detailing non-compliance issues.
  2. A-trust representative — Confirmed that all certificates reported have been revoked.
  3. A-trust representative — Provided a closure summary detailing the incident and remediation actions taken.
Participants
A-trust representative Community commenter Binaryparadox representative DigiCert Sectigo HARICA CCADB representative
External References
Similar Local Cases
#2016585 RESOLVED Self Reported Incident Incident Opened 2026-02-12 · Closed 2026-06-15 · 86% similar
IdenTrust: Test Certificates from cross-signed roots not disclosed in CT Logs
#2001327 RESOLVED Incident Revocation Issue Opened 2025-11-20 · Closed 2026-01-05 · 85% similar
NETLOCK: Missing CDP Disclosure in CCADB
#2033170 RESOLVED Ca Security Vulnerability Incident Self Reported Incident Revocation Issue Opened 2026-04-18 · Closed 2026-07-20 · 84% similar
DigiCert: Misissued code signing certificates
#2016672 RESOLVED Incident Revocation Issue Opened 2026-02-13 · Closed 2026-03-30 · 84% similar
certSIGN: certificates with delayed SCT signature
#2012157 RESOLVED Self Reported Incident Revocation Issue Security Incident Opened 2026-01-23 · Closed 2026-03-08 · 84% similar
Actalis: Issuance of certificate using keys previously reported as compromised
#2014610 RESOLVED Self Reported Incident Incident Opened 2026-02-05 · Closed 2026-04-11 · 83% similar
IdenTrust: Root OCSP Signer certificate mis-issuance
#1978163 RESOLVED Self Reported Incident Opened 2025-07-18 · Closed 2025-10-29 · 82% similar
DigiCert: Re-use of WHOIS validation shortly after deadline
#1896108 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-05-10 · Closed 2024-09-06 · 82% similar
Telia: Certificates Issued with lower case value in subject:countryName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action