← IdenTrust Services, LLC cases
Bugzilla #2006483 Self Reported Incident

IdenTrust: CT Logging Mistakes

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

IdenTrust self-disclosed an incident related to its Certificate Transparency (CT) log configuration. The CA reviewed its CT log activity after a public discussion and confirmed a similar issue: a customer reported encountering the error net::ERR_CERTIFICATE_TRANSPARENCY_REQUIRED after deploying TLS certificates issued by IdenTrust. The root cause was the inclusion of a CT log with a “Qualified” status for 2027 rather than one marked as “Usable.” IdenTrust remediated the issue by removing the “Qualified” log from its configuration and instructing the customer to replace the affected certificates. The incident report states that issuance remained unaffected because the CT log was cleared from the internal list within two hours, and it describes revocation of affected internal and customer certificates on 2025-12-19 and 2025-12-30. In the closure summary, IdenTrust requested closure after stating that all disclosed action items were completed as described.

Model: gpt-5.4-nano Generated: 2026-06-13 21:33 UTC Revised: 2026-06-16 19:29 UTC Confidence: 0.90 7 comments
Chronology
  1. IdenTrust enabled a CT log (“Argon2027h1”) with “Qualified” status in its systems.
  2. IdenTrust removed the “Argon2027h1” qualified CT log from its systems.
  3. IdenTrust revoked 46 internal certificates associated with the incident.
  4. IdenTrust revoked the remaining 3 certificates.
Thread Activity
  1. IdenTrust Services, LLC — IdenTrust provided a preliminary incident report describing the CT logging mistake, the customer error net::ERR_CERTIFICATE_TRANSPARENCY_REQUIRED, and initial remediation steps.
  2. IdenTrust Services, LLC — IdenTrust posted the full incident report with timeline, certificate counts, revocation details, and stated that issuance remained unaffected due to clearing the CT log within two hours.
  3. IdenTrust Services, LLC — IdenTrust created an attachment containing a full-qualified list CSV.
  4. IdenTrust Services, LLC — IdenTrust posted a report closure summary stating the incident cause, remediation (removing the Qualified log), and that action items were completed, requesting closure.
  5. CCADB representative — CCADB incident reporting issued a final call for comments or questions before closure.
  6. Mm representative — A commenter asked IdenTrust to expand on what the planned review process would entail and when using a Qualified log would be justified.
  7. IdenTrust Services, LLC — IdenTrust explained that the review would consider cases where Qualified logs may be appropriate due to limited usable logs, operator diversity needs, and early adoption testing with a new log operator.
Participants
IdenTrust Services, LLC CCADB representative Mm representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2025914 RESOLVED Self Reported Incident Audit Delay Opened 2026-03-24 · Closed 2026-05-18 · 98% similar
IdenTrust: Full Incident Report for bug 2014610 was not published within 14 days of discovering the issue
#2025917 RESOLVED Self Reported Incident Audit Delay Opened 2026-03-24 · Closed 2026-05-18 · 98% similar
IdenTrust: Full Incident Report for bug 2016585 was not published within 14 days of discovering the issue
#2026351 RESOLVED Self Reported Incident Certificate Misissuance Opened 2026-03-25 · Closed 2026-05-18 · 98% similar
Identrust: Root CrossSign, of dedicated Roots, missing EKU
#1991215 RESOLVED Self Reported Incident Opened 2025-09-26 · Closed 2025-11-21 · 97% similar
IdenTrust: ICA with invalid CDP
#1991558 RESOLVED Self Reported Incident Opened 2025-09-29 · Closed 2026-01-15 · 97% similar
IdenTrust: TLS self audit testing below 3%
#2014590 RESOLVED Self Reported Incident Incident Opened 2026-02-04 · Closed 2026-04-23 · 97% similar
IdenTrust: Unauthorized OCSP responses for cross-signed roots
#2014610 RESOLVED Self Reported Incident Incident Opened 2026-02-05 · Closed 2026-04-11 · 97% similar
IdenTrust: Root OCSP Signer certificate mis-issuance
#2025913 RESOLVED Self Reported Incident Incident Opened 2026-03-24 · Closed 2026-05-18 · 97% similar
IdenTrust: Full Incident Report for Bug 2014609 was not published within 14 days of discovering the issue

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action