IdenTrust: Root OCSP Signer certificate mis-issuance
IdenTrust Services, LLC self-disclosed a mis-issuance incident involving an OCSP signer certificate created using an incorrect Certificate Signing Request (CSR). This mis-issuance was identified while investigating unauthorized OCSP responses related to another incident. The CA reported that the mis-issuance resulted in invalid OCSP responses for the affected Root CA. A full incident report was submitted on February 18, 2026, detailing the root cause and remediation steps taken, including the implementation of hash validation checks to prevent future occurrences. The incident was resolved with the correct OCSP signer certificate generated and the necessary action items completed.
- OCSP Certificate created
- Non-compliance identified
- Preliminary Incident Report disclosed
- Full Incident Report submitted
- Validation checks for CSR signing completed
- Incident report closure expected
- IdenTrust Services, LLC — Preliminary Incident Report disclosed detailing the mis-issuance.
- IdenTrust Services, LLC — Full Incident Report submitted with detailed analysis and remediation steps.
- IdenTrust Services, LLC — Action item for environment-specific validation checks completed.
- CCADB representative — Final call for comments on the Incident Report before closure.