← IdenTrust Services, LLC cases
Bugzilla #2004492 Self Reported Incident Policy Document Issue

IdenTrust: CA Certificate not published in DER Encoded Format

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

IdenTrust self-disclosed an incident discovered during review of a cross-signed root CA in a staging environment. The issue was that the file referenced by the id-ad-caIssuers value in the Authority Information Access (AIA) extension of a production subordinate CA certificate was provided in PEM format rather than the DER-encoded format expected by RFC 5280 and the CA/Browser Forum Server Certificate Baseline Requirements. The CA owner stated that the impact was limited to the referenced file and that it did not affect the CA server certificate itself; issuance was not stopped because no certificate misissuance was involved. IdenTrust corrected the id-ad-caIssuers file to be DER format and reported that all other production subordinate CA certificates were reviewed and their id-ad-caIssuers values confirmed to be in DER format. In the incident report, IdenTrust attributed the problem to missing monitoring and missing automation at the time the non-compliance began (2020-08-12). The report describes remediation including correcting the file format and implementing automated validation and post-issuance verification controls, and IdenTrust requested closure after updating the action items as completed.

Model: gpt-5.4-nano Generated: 2026-06-13 21:33 UTC Revised: 2026-06-16 19:28 UTC Confidence: 0.90 8 comments
Chronology
  1. A subordinate CA was issued with an id-ad-caIssuers file referenced in the AIA extension provided in PEM format.
  2. The PEM vs DER discrepancy for the id-ad-caIssuers referenced file was identified.
  3. The id-ad-caIssuers file was corrected to DER format.
  4. Action items related to monitoring/validation were reported as completed per the updated incident report.
Thread Activity
  1. IdenTrust Services, LLC — Provided a preliminary incident report stating the id-ad-caIssuers file was in PEM format instead of DER, and that the corrected DER file was uploaded.
  2. IdenTrust Services, LLC — Submitted the full incident report with timeline, impact details (1 remaining valid TLS subordinate CA certificate), root cause analysis (missing monitoring and automation), and action items.
  3. IdenTrust Services, LLC — Reported automation implementation for Root Cause #2 and requested aligning the CCADB “Next update” field with the expected completion date.
  4. IdenTrust Services, LLC — Updated the action items table and included a report closure summary stating remediation controls were implemented and action items were completed.
  5. IdenTrust Services, LLC — Requested closure, stating all disclosed action items had been completed as described.
  6. CCADB representative — Noted the report had gone stale and reminded the CA owner about requesting a “Next update” date.
  7. CCADB representative — Issued a final call for comments and stated the incident report would be closed around 2026-02-05.
Participants
IdenTrust Services, LLC CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2016585 RESOLVED Self Reported Incident Incident Opened 2026-02-12 · Closed 2026-06-15 · 89% similar
IdenTrust: Test Certificates from cross-signed roots not disclosed in CT Logs
#2006483 RESOLVED Self Reported Incident Opened 2025-12-16 · Closed 2026-01-20 · 88% similar
IdenTrust: CT Logging Mistakes
#2014590 RESOLVED Self Reported Incident Incident Opened 2026-02-04 · Closed 2026-04-23 · 88% similar
IdenTrust: Unauthorized OCSP responses for cross-signed roots
#2026351 RESOLVED Self Reported Incident Certificate Misissuance Opened 2026-03-25 · Closed 2026-05-18 · 88% similar
Identrust: Root CrossSign, of dedicated Roots, missing EKU
#1991215 RESOLVED Self Reported Incident Opened 2025-09-26 · Closed 2025-11-21 · 87% similar
IdenTrust: ICA with invalid CDP
#1991558 RESOLVED Self Reported Incident Opened 2025-09-29 · Closed 2026-01-15 · 87% similar
IdenTrust: TLS self audit testing below 3%
#2014609 RESOLVED Self Reported Incident Certificate Misissuance Opened 2026-02-05 · Closed 2026-04-11 · 87% similar
IdenTrust: Cross-signed root certificate mis-issuance
#2025595 RESOLVED Self Reported Incident Incident Opened 2026-03-23 · Closed 2026-05-18 · 87% similar
IdenTrust: Delay in updating a Bug 2014609 - Next update

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action