← IdenTrust Services, LLC cases
Bugzilla #2014609
Self Reported Incident
Certificate Misissuance
IdenTrust: Cross-signed root certificate mis-issuance
RESOLVED
FIXED
IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
IdenTrust Services, LLC self-disclosed a mis-issuance incident involving a cross-signed root certificate. The mis-issuance was identified during cert-chain validation testing, where it was found that an incorrect Certificate Signing Request (CSR) was used. The CA promptly revoked the mis-issued certificate and implemented hash validation checks in their signing scripts to prevent future occurrences. A full incident report was submitted on February 18, 2026, detailing the incident and corrective actions taken. The case is now resolved with all action items completed.
Chronology
- Issued the cross-signed certificate
- Discovered the mis-issuance
- Revoked the mis-issued certificate
- Submitted full incident report
- Completed action items and requested closure
Thread Activity
- IdenTrust Services, LLC — Disclosed preliminary incident report regarding the mis-issuance.
- IdenTrust Services, LLC — Submitted full incident report detailing the mis-issuance and corrective actions.
- IdenTrust Services, LLC — Provided closure summary and confirmed completion of all action items.
Participants
IdenTrust Services, LLC
Apple representative
Community commenter
CCADB representative
External References
Similar Local Cases
IdenTrust: Approval of TLS certificate renewal without domain validation
IdenTrust: ICA with invalid CDP
IdenTrust: Unauthorized OCSP responses for cross-signed roots
IdenTrust: Root OCSP Signer certificate mis-issuance
IdenTrust: Test Certificates from cross-signed roots not disclosed in CT Logs
Identrust: Root CrossSign, of dedicated Roots, missing EKU
IdenTrust: Invalid special characters in S/MIME Certificates
IdenTrust: TLS self audit testing below 3%