← TrustAsia Technologies, Inc. cases
Bugzilla #2011713 Certificate Misissuance

TrustAsia: ACME Authorization Reuse Non-Compliance

RESOLVED FIXED TrustAsia Technologies, Inc.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

TrustAsia Technologies, Inc. reported a vulnerability in their LiteSSL ACME service that led to the reuse of domain validation records across different ACME accounts, resulting in the misissuance of 143 DV certificates. The issue was identified on January 21, 2026, following a report from a community security researcher. TrustAsia suspended the ACME issuance service, revoked all affected certificates, and implemented a fix on the same day. A full incident report was subsequently published detailing the timeline, root causes, and remediation steps taken. The case has been resolved with all action items completed.

Model: gpt-4o-mini Generated: 2026-06-13 20:15 UTC Revised: 2026-06-16 18:13 UTC Confidence: 0.90 12 comments
Chronology
  1. TrustAsia received a report indicating a vulnerability in their ACME service.
  2. All affected certificates were revoked and the service was restored.
  3. TrustAsia submitted a report closure summary detailing the incident and remediation.
Thread Activity
  1. TrustAsia Technologies, Inc. — Created preliminary incident report detailing the vulnerability and response.
  2. Community commenter — Questioned the timeline regarding the start of non-compliance.
  3. TrustAsia Technologies, Inc. — Submitted a full incident report with detailed findings and actions taken.
  4. TrustAsia Technologies, Inc. — Provided a report closure summary confirming completion of all action items.
Participants
TrustAsia Technologies, Inc. Community commenter CCADB representative
External References
Similar Local Cases
#2011865 RESOLVED Certificate Misissuance Opened 2026-01-22 · Closed 2026-03-17 · 96% similar
TrustAsia: SSL DV Mis-issuance against CP/CPS (IPAddress)
#1961406 RESOLVED Certificate Misissuance Opened 2025-04-18 · Closed 2025-07-02 · 78% similar
SSL.com: DCV bypass and issue fake certificates for any MX hostname
#1956910 RESOLVED Certificate Misissuance Opened 2025-03-27 · Closed 2025-07-16 · 78% similar
Chunghwa Telecom: OV TLS Server certificate issuance by GTLSCA without proper validation
#1986968 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-09-04 · Closed 2026-04-06 · 76% similar
Financijska agencija (Fina): Mis-issued certificates
#1959721 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-04-10 · Closed 2025-06-12 · 75% similar
Lawtrust: The S/MIME CA’s policy identifiers did not align with the CA/Browser Forum Requirements.
#1963663 RESOLVED Incident Certificate Misissuance Opened 2025-04-30 · Closed 2025-06-12 · 74% similar
Certigna: Multiple Reserved Certificate Policy Identifiers in CA certificates
#1965459 RESOLVED Certificate Misissuance Self Reported Incident Opened 2025-05-09 · Closed 2025-10-31 · 72% similar
Telia: S/MIME Misissuance incorrect AIA id-ca-caIssuer http:URI
#2012274 RESOLVED Self Reported Incident Certificate Misissuance Revocation Issue Opened 2026-01-24 · Closed 2026-03-08 · 72% similar
Chunghwa Telecom: Issuance of certificate using keys previously reported as compromised

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action