← IdenTrust Services, LLC cases
Bugzilla #2026351 Self Reported Incident Certificate Misissuance

Identrust: Root cross-signs of dedicated roots missing required EKU at the root level

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

IdenTrust reported an incident involving recent root cross-signs of dedicated roots where the dedicated Root certificates were missing the required EKU presence for their respective chains. The issue was that issuing CAs underneath these dedicated roots asserted EKUs, but the EKU was additionally required at the Root level for cross-signing with multi-purpose roots. IdenTrust stated the non-compliance began on 2026-01-26, was identified on 2026-03-24, and ended on 2026-03-28. The incident was disclosed after a third party notified IdenTrust of the missing EKU on 2026-03-24, and IdenTrust submitted both a preliminary and a full incident report. IdenTrust revoked the affected cross-signed root certificates on 2026-03-28 and updated relevant certificate profiles to include the EKU(s). IdenTrust also added an issuance check for compliance with CCADB Policy Section 6.3, and reported that all action items were completed, requesting closure; the bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:38 UTC Revised: 2026-06-16 19:31 UTC Confidence: 0.86 9 comments
Chronology
  1. IdenTrust issued multiple cross-signed root certificates for dedicated roots without EKU assertion.
  2. IdenTrust was notified by a third party that the cross-signed root certificates were missing required EKU presence.
  3. IdenTrust revoked the affected cross-signed root certificates.
  4. Mozilla CA Program bug marked RESOLVED (FIXED).
Thread Activity
  1. IdenTrust Services, LLC — Submitted a Preliminary Incident Report describing missing EKU presence on dedicated root cross-signs and citing CCADB Policy 6.3.
  2. IdenTrust Services, LLC — Announced a plan to publish the full incident report by the end of the week.
  3. IdenTrust Services, LLC — Submitted the Full Incident Report with timeline, impact (6 total certificates; 0 remaining valid), and root cause analysis.
  4. IdenTrust Services, LLC — Provided action items including updating certificate profiles to include EKU(s) and adding an issuance check for CCADB Policy 6.3 compliance.
  5. IdenTrust Services, LLC — Reported certificate profile updates as complete and continued investigating the issuance check, requesting a next-update field of 2026-04-30.
  6. IdenTrust Services, LLC — Reported the issuance check for missing EKUs in root cross-sign scenarios as implemented (complete).
  7. IdenTrust Services, LLC — Stated all action items were completed and that a closure report would be submitted by end of the week.
  8. IdenTrust Services, LLC — Submitted the Report Closure Summary, stating remediation (revocation, certprofile updates, issuance check) and requesting closure.
  9. CCADB representative — Issued a final call for comments or questions before closure on approximately 2026-05-18.
Participants
IdenTrust Services, LLC CCADB representative
Similar Local Cases
#1910195 RESOLVED Certificate Misissuance Self Reported Incident Opened 2024-07-26 · Closed 2024-09-06 · 100% similar
IdenTrust: Invalid special characters in S/MIME Certificates
#2014609 RESOLVED Self Reported Incident Certificate Misissuance Opened 2026-02-05 · Closed 2026-04-11 · 100% similar
IdenTrust: Cross-signed root certificate mis-issuance
#1853783 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2023-09-18 · Closed 2025-03-20 · 99% similar
IdenTrust: S/MIME certificates issued in violation of New S/MIME Baseline Requirements v1.0
#1991558 RESOLVED Self Reported Incident Opened 2025-09-29 · Closed 2026-01-15 · 99% similar
IdenTrust: TLS self audit testing below 3%
#2014590 RESOLVED Self Reported Incident Incident Opened 2026-02-04 · Closed 2026-04-23 · 99% similar
IdenTrust: Unauthorized OCSP responses for cross-signed roots
#2025596 RESOLVED Self Reported Incident Incident Opened 2026-03-23 · Closed 2026-05-18 · 99% similar
IdenTrust: Delay in updating a Bugzilla ticket Bug 2014610 - Next update
#2025914 RESOLVED Self Reported Incident Audit Delay Opened 2026-03-24 · Closed 2026-05-18 · 99% similar
IdenTrust: Full Incident Report for bug 2014610 was not published within 14 days of discovering the issue
#2025917 RESOLVED Self Reported Incident Audit Delay Opened 2026-03-24 · Closed 2026-05-18 · 99% similar
IdenTrust: Full Incident Report for bug 2016585 was not published within 14 days of discovering the issue

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action