IdenTrust: Test Certificates from cross-signed roots not disclosed in CT Logs
IdenTrust self-disclosed an incident involving test automation certificates that failed browser validation due to missing Certificate Transparency (CT) log entries. The issue was identified during a review and was limited to test certificates from a newly cross-signed TLS CA hierarchy. No customer certificates were affected. The CA revoked the impacted certificates and issued new ones with proper CT log submissions. A full incident report was disclosed on February 26, 2026, detailing the timeline and remediation steps taken, including the implementation of post-issuance CT linting to prevent future occurrences.
- Non-compliance start date identified.
- Non-compliance identified and affected certificates revoked.
- Full incident report disclosed.
- IdenTrust Services, LLC — Preliminary incident report disclosed detailing the issue with test certificates.
- IdenTrust Services, LLC — Full incident report submitted with a summary of the incident and remediation actions.
- IdenTrust Services, LLC — Closure summary provided, confirming all action items have been completed.