← IdenTrust Services, LLC cases
Bugzilla #2014590 Self Reported Incident Incident

IdenTrust: Unauthorized OCSP responses for cross-signed roots

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

IdenTrust Services, LLC self-disclosed an incident involving unauthorized OCSP responses for four cross-signed certificates. The issue was identified during routine monitoring, revealing that the corresponding Intermediate Certificate Authorities (ICAs) were not included in the OCSP configuration prior to the certificates' disclosure to the Common CA Database (CCADB). A full incident report was submitted, detailing the timeline of events and root causes, including configuration gaps and process oversights. The CA has completed all action items to remediate the issue and has requested closure of the incident report.

Model: gpt-4o-mini Generated: 2026-06-13 21:34 UTC Revised: 2026-06-16 19:29 UTC Confidence: 0.85 11 comments
Chronology
  1. Non-compliance start date identified
  2. Non-compliance identified
  3. Preliminary incident disclosed
  4. Full incident report submitted
  5. Incident report closure requested
Thread Activity
  1. IdenTrust Services, LLC — Preliminary incident report submitted detailing unauthorized OCSP responses.
  2. Community commenter — Questioned the self-disclosure claim due to reliance on a third-party tool.
  3. IdenTrust Services, LLC — Full incident report provided with detailed analysis and action items.
  4. IdenTrust Services, LLC — Requested closure of the incident report.
  5. CCADB representative — Final call for comments before closure of the incident report.
Participants
IdenTrust Services, LLC Community commenter CCADB representative
External References
Similar Local Cases
#2014609 RESOLVED Self Reported Incident Certificate Misissuance Opened 2026-02-05 · Closed 2026-04-11 · 100% similar
IdenTrust: Cross-signed root certificate mis-issuance
#2014610 RESOLVED Self Reported Incident Incident Opened 2026-02-05 · Closed 2026-04-11 · 100% similar
IdenTrust: Root OCSP Signer certificate mis-issuance
#2016267 RESOLVED Self Reported Incident Incident Opened 2026-02-11 · Closed 2026-04-17 · 100% similar
IdenTrust: Gap between audit periods
#2016585 RESOLVED Self Reported Incident Incident Opened 2026-02-12 · Closed 2026-06-15 · 100% similar
IdenTrust: Test Certificates from cross-signed roots not disclosed in CT Logs
#2025595 RESOLVED Self Reported Incident Incident Opened 2026-03-23 · Closed 2026-05-18 · 100% similar
IdenTrust: Delay in updating a Bug 2014609 - Next update
#2025596 RESOLVED Self Reported Incident Incident Opened 2026-03-23 · Closed 2026-05-18 · 100% similar
IdenTrust: Delay in updating a Bugzilla ticket Bug 2014610 - Next update
#2025913 RESOLVED Self Reported Incident Incident Opened 2026-03-24 · Closed 2026-05-18 · 100% similar
IdenTrust: Full Incident Report for Bug 2014609 was not published within 14 days of discovering the issue
#2026351 RESOLVED Self Reported Incident Certificate Misissuance Opened 2026-03-25 · Closed 2026-05-18 · 99% similar
Identrust: Root CrossSign, of dedicated Roots, missing EKU

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action