IdenTrust: CA Certificate not published in DER Encoded Format
IdenTrust self-disclosed an incident discovered during review of a cross-signed root CA in a staging environment. The issue was that the file referenced by the id-ad-caIssuers value in the Authority Information Access (AIA) extension of a production subordinate CA certificate was provided in PEM format rather than the DER-encoded format expected by RFC 5280 and the CA/Browser Forum Server Certificate Baseline Requirements. The CA owner stated that the impact was limited to the referenced file and that it did not affect the CA server certificate itself; issuance was not stopped because no certificate misissuance was involved. IdenTrust corrected the id-ad-caIssuers file to be DER format and reported that all other production subordinate CA certificates were reviewed and their id-ad-caIssuers values confirmed to be in DER format. In the incident report, IdenTrust attributed the problem to missing monitoring and missing automation at the time the non-compliance began (2020-08-12). The report describes remediation including correcting the file format and implementing automated validation and post-issuance verification controls, and IdenTrust requested closure after updating the action items as completed.
- A subordinate CA was issued with an id-ad-caIssuers file referenced in the AIA extension provided in PEM format.
- The PEM vs DER discrepancy for the id-ad-caIssuers referenced file was identified.
- The id-ad-caIssuers file was corrected to DER format.
- Action items related to monitoring/validation were reported as completed per the updated incident report.
- IdenTrust Services, LLC — Provided a preliminary incident report stating the id-ad-caIssuers file was in PEM format instead of DER, and that the corrected DER file was uploaded.
- IdenTrust Services, LLC — Submitted the full incident report with timeline, impact details (1 remaining valid TLS subordinate CA certificate), root cause analysis (missing monitoring and automation), and action items.
- IdenTrust Services, LLC — Reported automation implementation for Root Cause #2 and requested aligning the CCADB “Next update” field with the expected completion date.
- IdenTrust Services, LLC — Updated the action items table and included a report closure summary stating remediation controls were implemented and action items were completed.
- IdenTrust Services, LLC — Requested closure, stating all disclosed action items had been completed as described.
- CCADB representative — Noted the report had gone stale and reminded the CA owner about requesting a “Next update” date.
- CCADB representative — Issued a final call for comments and stated the incident report would be closed around 2026-02-05.