← IdenTrust Services, LLC cases
Bugzilla #2006483
Certificate Misissuance
IdenTrust: CT Logging Mistakes
RESOLVED
FIXED
IdenTrust Services, LLC
AI Summary
IdenTrust Services, LLC self-disclosed a Certificate Transparency (CT) logging mistake that affected TLS certificates issued by them. The issue arose from the inclusion of a CT log with a 'Qualified' status instead of a 'Usable' one, leading to errors for at least one customer. The CA has since removed the problematic log and instructed the customer to replace the affected certificates. A full incident report was provided, detailing the timeline and remediation steps taken.
Chronology
- Enabled 'Argon2027h1' (qualified CT log) in systems
- Customer reported encountering the error net::ERR_CERTIFICATE_TRANSPARENCY_REQUIRED
- Removed 'Argon2027h1' from systems
- Revoked 46 internal certificates
- Revoked 3 remaining customer certificates
- Incident report closure requested
Participants
IdenTrust
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
IdenTrust: Improper encoding of wildcard certificate
IdenTrust: Issuance of Subordinate CA’s Without EKU
IdenTrust: test certificates inadvertently published in production environment
IdenTrust: Root OCSP Signer certificate mis-issuance
IdenTrust: ICA with invalid CDP
IdenTrust: Issuance of certificates greater than 398 days
IdenTrust: Inconsistent Disclosure of Externally-Operated Intermediate
IdenTrust: Validation Source for EV Certificates not Publicly Disclosed