TrustAsia: SSL DV mis-issuance against CP/CPS (IP addresses in DV certificates)
TrustAsia reported a self-discovered compliance incident involving its Intermediate CA “宝塔 DV TLS RSA CA 2025”. During an internal correlation review for Bug 2011713, TrustAsia’s compliance team found that the ICA had issued 123 DV SSL certificates containing IP addresses between 2025-11-24 and 2026-01-22, which violated Section 3.1.1 of TrustAsia’s CP/CPS v2.1.0 (IP addresses are not allowed in DV certificates). After confirming the violation, TrustAsia implemented immediate remediation, including rolling back certificate system configuration and rejecting DV certificate orders containing IP addresses, and it updated certificate profiles to technically prevent such issuances. TrustAsia also revoked all affected certificates, stating that all 123 were revoked by 2026-01-24. The thread includes a corrected incident report that addressed an ICA name misidentification in the preliminary report and an omitted certificate, and it describes additional prevention measures such as custom pre-issuance linting tools and a mandatory “Change Checklist” for configuration changes. The bug is marked RESOLVED with resolution FIXED, and TrustAsia requested closure after completing the disclosed action items.
- TrustAsia’s “宝塔 DV TLS RSA CA 2025” began issuing DV SSL certificates containing IP addresses (non-compliant behavior).
- TrustAsia’s compliance team identified the CP/CPS violation during an internal review and began blocking and remediating IP-containing DV issuance.
- TrustAsia completed revocation of all affected DV IP certificates and finalized the incident report corrections.
- Mozilla CA Program incident report closure was scheduled/expected around this date.
- TrustAsia Technologies, Inc. — Created a preliminary incident report stating TrustAsia discovered that the ICA had issued 122 DV IP certificates (one already revoked) in violation of CP/CPS Section 3.1.1 and that it would revoke non-compliant certificates within 5 days.
- TrustAsia Technologies, Inc. — Reported that all affected certificates had been revoked.
- TrustAsia Technologies, Inc. — Provided an information correction: the ICA name was corrected to “宝塔 DV TLS RSA CA 2025,” the affected certificate count was updated to 123, and all were confirmed revoked.
- TrustAsia Technologies, Inc. — Stated that investigation was in progress and a full incident report would follow.
- TrustAsia Technologies, Inc. — Submitted a full incident report describing the incident, impact (123 certificates, 0 remaining valid), revocation by 2026-01-24, and remediation/prevention steps.
- TrustAsia Technologies, Inc. — Requested setting the “Next update” date to 2026-03-05 for in-progress action items.
- TrustAsia Technologies, Inc. — Reported completion of all action items and said a report closure summary would be posted soon.
- TrustAsia Technologies, Inc. — Posted the report closure summary, stating all action items were completed and requesting closure.
- CCADB representative — Issued a final call for comments/questions and noted the bug would be closed approximately 2026-03-17.