← iTrusChina Co., Ltd. cases
Bugzilla #2013805
CCADB Compliance
iTrusChina: Finding in Routine WebTrust Audit - Domain validation records without the TLS BR version
RESOLVED
FIXED
iTrusChina Co., Ltd.
AI Summary
During the 2025 WebTrust audit, iTrusChina was informed that its domain validation records did not include the required TLS Baseline version, violating WebTrust for CA – TLS Baseline V2.9. In response, iTrusChina halted new TLS certificate issuance and initiated a root cause analysis. The issue stemmed from a misunderstanding of TLS BR requirements and flaws in the RA system design. iTrusChina has since updated its RA system to ensure compliance and trained its staff on the necessary requirements.
Chronology
- Non-compliance start date
- Non-compliance identified date
- Internal departments began root cause analysis
- RA system updated to fix the problem
- Report Closure Summary submitted
Participants
vTrus_contact@itrus.cn
External References
Similar Local Cases
iTrusChina: Failure to Provide Regular Incident Update
TWCA: Intermediate CA Certificate Missing from Audit Reports
SECOM: Intermediate CA Certificates Missing from Audit Reports
DigiCert: Late CP/CPS CCADB uploads
Firmaprofesional: 2019 audit Finding #2 - 6.4 Facility, management, and operational controls
SECOM: Incorrect CCADB Non-Audit Document References for FUJIFILM Fnet CA - C
Sectigo: CCADB failed ALV - Network Solutions Certificate Authority
Microsoft PKI Services: Incomplete Logical Access Review Audit Evidence