← iTrusChina Co., Ltd. cases
Bugzilla #2013805 Ca Certificate Compliance

iTrusChina: Finding in Routine WebTrust Audit - Domain validation records without the TLS BR version

RESOLVED FIXED iTrusChina Co., Ltd.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

During the 2025 WebTrust annual audit, iTrusChina discovered that its domain validation records lacked the required TLS Baseline version, violating WebTrust and TLS BR requirements. In response, iTrusChina halted new certificate issuance and initiated an investigation into the root causes. The audit finding was disclosed, and a full incident report was provided, detailing the non-compliance period and corrective actions taken. The RA system was updated to include the TLS BR version number for domain validations, and staff training was conducted to improve understanding of compliance requirements. The case has been resolved with all action items completed.

Model: gpt-4o-mini Generated: 2026-06-13 21:13 UTC Revised: 2026-06-16 19:12 UTC Confidence: 0.85 15 comments
Chronology
  1. iTrusChina was notified of non-compliance during the WebTrust audit.
  2. iTrusChina updated the RA system to fix the issue.
  3. iTrusChina submitted a report closure summary and requested closure of the incident.
Thread Activity
  1. iTrusChina Co., Ltd. — iTrusChina reported the incident discovered during the WebTrust audit.
  2. iTrusChina Co., Ltd. — iTrusChina provided a full incident report detailing the findings.
  3. iTrusChina Co., Ltd. — iTrusChina submitted the report closure summary and confirmed all actions were completed.
Participants
iTrusChina Co., Ltd. CCADB representative
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#1712664 RESOLVED Ca Certificate Compliance Opened 2021-05-25 · Closed 2023-02-22 · 87% similar
iTrusChina: verification errors for the roots' CRLs(ARL)
#1907949 RESOLVED Ca Certificate Compliance Opened 2024-07-15 · Closed 2024-08-28 · 81% similar
iTrusChina: CRL Reason Codes
#2019995 RESOLVED Ca Certificate Compliance Opened 2026-02-27 · Closed 2026-04-08 · 69% similar
Sectigo: Package patching gap within Certificate Systems
#1963456 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-04-29 · Closed 2025-07-25 · 69% similar
GoDaddy: CA Certificates with HTTPS URL in AIA Field
#2009543 RESOLVED Ca Certificate Compliance Incident Repository Issue Opened 2026-01-10 · Closed 2026-02-09 · 68% similar
Microsoft PKI Services: Improper Disclosure of CRLs – Does Not Match CA Subject
#1957962 RESOLVED Ca Certificate Compliance Opened 2025-04-02 · Closed 2025-07-16 · 68% similar
Telekom Security: QCStatement with http link to PDS
#2021550 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-03-06 · Closed 2026-03-26 · 68% similar
SECOM: 2025 S/MIME CA Modified Opinion Report of Cybertrust Japan (CTJ)
#1969296 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-05-29 · Closed 2025-07-22 · 68% similar
GoDaddy: Certificates with invalid embedded SCT signatures

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action