← IdenTrust Services, LLC cases
Bugzilla #2014610 Certificate Misissuance

IdenTrust: Root OCSP Signer certificate mis-issuance

RESOLVED FIXED IdenTrust Services, LLC
AI Summary

IdenTrust Services, LLC reported a mis-issuance of an OCSP signer certificate due to an incorrect Certificate Signing Request (CSR) being used. This incident was identified while investigating unauthorized OCSP responses related to another case. The mis-issuance resulted in invalid OCSP responses for the affected Root CA, but no other certificates were impacted. The root cause was traced to an ambiguous directory structure for CSR storage, which allowed the wrong CSR to be selected. Remediation measures, including the implementation of hash validation checks, have been completed to prevent future occurrences.

Model: gpt-4o-mini Generated: 2026-06-13 21:34 UTC Confidence: 0.90
Chronology
  1. OCSP Certificate created
  2. Issuance of cross-signed certificates
  3. Non-compliance identified
  4. Preliminary Incident Report disclosed
  5. Full Incident Report disclosed
  6. Validation checks for CSR signing completed
  7. Incident report closure expected
Participants
IdenTrust
Similar Local Cases
#1910195 RESOLVED Certificate Misissuance Opened 2024-07-26 · Closed 2024-09-06 · 60% similar
IdenTrust: Invalid special characters in S/MIME Certificates
#1446121 RESOLVED Certificate Misissuance Opened 2018-03-15 · Closed 2023-02-22 · 60% similar
IdenTrust: Improper encoding of wildcard certificate
#1669594 RESOLVED Certificate Misissuance Opened 2020-10-06 · Closed 2023-02-22 · 59% similar
IdenTrust: Issuance of Subordinate CA’s Without EKU
#1753287 RESOLVED Certificate Misissuance Opened 2022-02-02 · Closed 2024-07-08 · 59% similar
IdenTrust: Validation Source for EV Certificates not Publicly Disclosed
#1876871 RESOLVED Certificate Misissuance Opened 2024-01-26 · Closed 2024-06-30 · 58% similar
IdenTrust: test certificates inadvertently published in production environment
#1930029 RESOLVED Certificate Misissuance Opened 2024-11-08 · Closed 2025-02-19 · 58% similar
IdenTrust: Approval of TLS certificate renewal without domain validation
#1991215 RESOLVED Certificate Misissuance Opened 2025-09-26 · Closed 2025-11-21 · 58% similar
IdenTrust: ICA with invalid CDP
#2014609 RESOLVED Certificate Misissuance Opened 2026-02-05 · Closed 2026-04-11 · 58% similar
IdenTrust: Cross-signed root certificate mis-issuance

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action