TrustAsia: ACME Authorization Reuse Non-Compliance
TrustAsia Technologies, Inc. reported a vulnerability in their LiteSSL ACME service that led to the reuse of domain validation records across different ACME accounts, resulting in the misissuance of 143 DV certificates. The issue was identified on January 21, 2026, following a report from a community security researcher. TrustAsia suspended the ACME issuance service, revoked all affected certificates, and implemented a fix on the same day. A full incident report was subsequently published detailing the timeline, root causes, and remediation steps taken. The case has been resolved with all action items completed.
- TrustAsia received a report indicating a vulnerability in their ACME service.
- All affected certificates were revoked and the service was restored.
- TrustAsia submitted a report closure summary detailing the incident and remediation.
- TrustAsia Technologies, Inc. — Created preliminary incident report detailing the vulnerability and response.
- Community commenter — Questioned the timeline regarding the start of non-compliance.
- TrustAsia Technologies, Inc. — Submitted a full incident report with detailed findings and actions taken.
- TrustAsia Technologies, Inc. — Provided a report closure summary confirming completion of all action items.