← TrustAsia Technologies, Inc. cases
Bugzilla #2011865 Certificate Misissuance

TrustAsia: SSL DV mis-issuance against CP/CPS (IP addresses in DV certificates)

RESOLVED FIXED TrustAsia Technologies, Inc.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

TrustAsia reported a self-discovered compliance incident involving its Intermediate CA “宝塔 DV TLS RSA CA 2025”. During an internal correlation review for Bug 2011713, TrustAsia’s compliance team found that the ICA had issued 123 DV SSL certificates containing IP addresses between 2025-11-24 and 2026-01-22, which violated Section 3.1.1 of TrustAsia’s CP/CPS v2.1.0 (IP addresses are not allowed in DV certificates). After confirming the violation, TrustAsia implemented immediate remediation, including rolling back certificate system configuration and rejecting DV certificate orders containing IP addresses, and it updated certificate profiles to technically prevent such issuances. TrustAsia also revoked all affected certificates, stating that all 123 were revoked by 2026-01-24. The thread includes a corrected incident report that addressed an ICA name misidentification in the preliminary report and an omitted certificate, and it describes additional prevention measures such as custom pre-issuance linting tools and a mandatory “Change Checklist” for configuration changes. The bug is marked RESOLVED with resolution FIXED, and TrustAsia requested closure after completing the disclosed action items.

Model: gpt-5.4-nano Generated: 2026-06-13 20:15 UTC Revised: 2026-06-16 18:13 UTC Confidence: 0.90 10 comments
Chronology
  1. TrustAsia’s “宝塔 DV TLS RSA CA 2025” began issuing DV SSL certificates containing IP addresses (non-compliant behavior).
  2. TrustAsia’s compliance team identified the CP/CPS violation during an internal review and began blocking and remediating IP-containing DV issuance.
  3. TrustAsia completed revocation of all affected DV IP certificates and finalized the incident report corrections.
  4. Mozilla CA Program incident report closure was scheduled/expected around this date.
Thread Activity
  1. TrustAsia Technologies, Inc. — Created a preliminary incident report stating TrustAsia discovered that the ICA had issued 122 DV IP certificates (one already revoked) in violation of CP/CPS Section 3.1.1 and that it would revoke non-compliant certificates within 5 days.
  2. TrustAsia Technologies, Inc. — Reported that all affected certificates had been revoked.
  3. TrustAsia Technologies, Inc. — Provided an information correction: the ICA name was corrected to “宝塔 DV TLS RSA CA 2025,” the affected certificate count was updated to 123, and all were confirmed revoked.
  4. TrustAsia Technologies, Inc. — Stated that investigation was in progress and a full incident report would follow.
  5. TrustAsia Technologies, Inc. — Submitted a full incident report describing the incident, impact (123 certificates, 0 remaining valid), revocation by 2026-01-24, and remediation/prevention steps.
  6. TrustAsia Technologies, Inc. — Requested setting the “Next update” date to 2026-03-05 for in-progress action items.
  7. TrustAsia Technologies, Inc. — Reported completion of all action items and said a report closure summary would be posted soon.
  8. TrustAsia Technologies, Inc. — Posted the report closure summary, stating all action items were completed and requesting closure.
  9. CCADB representative — Issued a final call for comments/questions and noted the bug would be closed approximately 2026-03-17.
Participants
TrustAsia Technologies, Inc. CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2011713 RESOLVED Certificate Misissuance Opened 2026-01-21 · Closed 2026-03-17 · 96% similar
TrustAsia: ACME Authorization Reuse Non-Compliance
#1963663 RESOLVED Incident Certificate Misissuance Opened 2025-04-30 · Closed 2025-06-12 · 75% similar
Certigna: Multiple Reserved Certificate Policy Identifiers in CA certificates
#1979475 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-07-26 · Closed 2026-01-20 · 72% similar
Microsoft PKI Services: End Entity Certificate Mis-issuance against CPS (BasicConstraints)
#2026351 RESOLVED Self Reported Incident Certificate Misissuance Opened 2026-03-25 · Closed 2026-05-18 · 71% similar
Identrust: Root CrossSign, of dedicated Roots, missing EKU
#1969036 RESOLVED Certificate Misissuance Opened 2025-05-28 · Closed 2025-10-31 · 71% similar
Telia: TLS incorrect AIA caIssuer URI and incorrect CDP
#2005939 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-12-14 · Closed 2026-03-13 · 71% similar
Microsec: CT Logging mistakes
#1956910 RESOLVED Certificate Misissuance Opened 2025-03-27 · Closed 2025-07-16 · 71% similar
Chunghwa Telecom: OV TLS Server certificate issuance by GTLSCA without proper validation
#1981680 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Linting Quality Issue Opened 2025-08-07 · Closed 2025-09-26 · 71% similar
TunTrust: SSL OV mis-issuance against CP/CPS (Email attribute)

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action