← D-TRUST cases
Bugzilla #1976837 Incident

D-Trust: Defective certificate incident reporting form (truncated internal notifications)

RESOLVED FIXED D-TRUST
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

D-TRUST reported a self-discovered issue with its certificate incident reporting web form at https://www.d-trust.net/en/support/reporting-certificate-problem. During external use of the form on 2025/07/09, D-TRUST found that certain reporter-provided contact information fields were not correctly included in the internal email notifications to the incident response team when a certain character limit was exceeded. D-TRUST stated that this affected only internal handling of incoming form data and did not impact the availability of the form. In the specific case on 2025/07/09, the incident team was unable to contact the reporter because the contact information was cut off, although the incident report information was transmitted and processed according to regular procedures. D-TRUST identified a size limitation in generating the internal notification email as the root cause and adjusted the size limitation on 2025/07/10 to prevent recurrence. D-TRUST retested the web form and revised its requirements engineering process on 2025/07/21, and requested closure of the incident report; the bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:33 UTC Revised: 2026-06-16 18:47 UTC Confidence: 0.90 5 comments
Chronology
  1. D-Trust released a new web form for certificate incident reports.
  2. During external use of the certificate incident reporting web form, internal email notifications truncated reporter contact information when character limits were exceeded.
  3. D-Trust adjusted the size limitation for internal email notifications to prevent the truncation issue from recurring.
  4. D-Trust revised its requirements engineering process for the web form.
  5. CCADB planned to close the incident report if no further comments were received.
Thread Activity
  1. Bdr representative — Opened a preliminary incident report stating that internal email notifications from the certificate incident reporting form omitted reporter contact fields when a character limit was exceeded.
  2. Bdr representative — Posted a full incident report with details including that no certificates were affected and that the issue prevented contacting the reporter due to truncated contact information.
  3. Bdr representative — Noted there was nothing new to report and that a closure report was being prepared.
  4. D-Trust — Submitted a closure report describing remediation (adjusted size limitation on 2025-07-10), retesting, and requirements process revisions on 2025-07-21, and requested closure.
  5. CCADB representative — Issued a final call for comments or questions before the incident report would be closed around 2025-08-18.
Participants
Bdr representative D-Trust CCADB representative
Similar Local Cases
#2009149 RESOLVED Incident Opened 2026-01-08 · Closed 2026-04-19 · 100% similar
D-Trust: Expired certificate provided on the CA TLS test website for demonstration of valid certificates
#2010600 RESOLVED Incident Opened 2026-01-15 · Closed 2026-02-27 · 100% similar
D-Trust: CRLs of CAs issuing CA certificates exceed the maximum validity period
#1682270 RESOLVED Ca Certificate Compliance Incident Closure Request Opened 2020-12-14 · Closed 2026-06-12 · 87% similar
D-TRUST: Private Key Disclosed by Customer as Part of CSR
#2037000 ASSIGNED Self Reported Incident Certificate Misissuance Problem Reporting Failure Opened 2026-05-05 Still Open · 86% similar
D-Trust: Missing Pre-Sign Linting for S/MIME Issuing CAs
#2007116 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Externally Reported Incident Opened 2025-12-19 Still Open · 84% similar
D-Trust: CRL URL Disclosure
#1963663 RESOLVED Incident Certificate Misissuance Opened 2025-04-30 · Closed 2025-06-12 · 75% similar
Certigna: Multiple Reserved Certificate Policy Identifiers in CA certificates
#1985307 RESOLVED Incident Opened 2025-08-26 · Closed 2025-10-09 · 69% similar
Sectigo: OCSP and CRL traffic not being proxied for 3 Subordinate CAs
#2025596 RESOLVED Self Reported Incident Incident Opened 2026-03-23 · Closed 2026-05-18 · 69% similar
IdenTrust: Delay in updating a Bugzilla ticket Bug 2014610 - Next update

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action