← D-TRUST cases
Bugzilla #2029013 Ca Certificate Compliance Incident Self Reported Incident Validation Issue Policy Document Issue

D-Trust self-disclosed TLS issuance control failure involving missing pre-sign linting

ASSIGNED D-TRUST
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

D-Trust reported a self-disclosed compliance incident involving its TLS issuance controls under CA/Browser Forum TLS Baseline Requirements Section 4.3.1.2. The company said its RA-side and CA-side pre-sign checks did not meet the intended linting requirement, which allowed non-compliant TLS certificates to be issued and logged. D-Trust stopped issuance from the affected part of its PKI on 2026-04-02 and resumed after deploying a compliant pre-sign linting solution. In its full incident report, D-Trust said 57,565 certificates were issued non-compliantly between 2025-03-15 and 2026-04-02, affecting DV, OV, and EV TLS certificates. D-Trust confirmed that all affected certificates had been revoked by 2026-04-07. The thread later shifted to follow-up discussion about mass revocation exercises and browser revocation handling, and D-Trust’s latest update said the remaining action item was still ongoing with a due date of 2026-09-30.

Model: gpt-5.4-mini Generated: 2026-06-13 21:36 UTC Revised: 2026-08-30 06:00 UTC Confidence: 0.97 19 comments
Chronology
  1. D-Trust continued issuing TLS certificates after the mandatory pre-sign linting requirement in Section 4.3.1.2 took effect.
  2. D-Trust stopped issuance from the affected part of its PKI and later resumed after deploying a compliant pre-sign linting solution.
  3. D-Trust completed revocation of all affected TLS certificates.
Thread Activity
  1. Bdr representative — D-Trust filed a preliminary incident report saying its internal checks did not satisfy the linting requirement and that it had stopped issuance pending remediation.
  2. Bdr representative — D-Trust confirmed that all affected TLS certificates had been revoked.
  3. Bdr representative — D-Trust said it had conducted mass revocation exercises on 2026-03-03 and 2026-03-24, with the latter performed as part of an independent third-party audit.
  4. Bdr representative — D-Trust posted a full incident report stating that 57,565 certificates were issued in violation of Section 4.3.1.2 and that the affected certificates had been revoked.
  5. Mozilla representative — Mozilla explained that CA revocation obligations and browser revocation enforcement are separate, and that browser vendors may respond more aggressively in active security threats.
  6. Bdr representative — D-Trust provided a weekly update saying there was nothing new to report and requested the next update deadline be set for 2026-08-29.
  7. D-Trust — D-Trust said the remaining action item was ongoing, the previously reported due date of 2026-09-30 was unchanged, and requested the next update date be set to 2026-09-30.
Participants
Bdr representative Heise representative Mozmail representative Mozilla representative D-Trust
Related Bugzilla IDs Mentioned
Similar Local Cases
#2007116 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Ccadb Disclosure Issue Opened 2025-12-19 · Closed 2026-09-03 · 96% similar
D-Trust: CRL URL Disclosure
#1682270 RESOLVED Ca Certificate Compliance Incident Closure Request Opened 2020-12-14 · Closed 2026-06-12 · 95% similar
D-TRUST: Private Key Disclosed by Customer as Part of CSR
#2037000 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-05-05 Still Open · 94% similar
D-Trust: Missing Pre-Sign Linting for S/MIME Issuing CAs
#2012511 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2026-01-26 · Closed 2026-04-19 · 93% similar
D-Trust: CRL HTTP Media Type
#2056223 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-07-20 · Closed 2026-08-08 · 90% similar
D-Trust OCSP Responder Certificates Include CA/B Forum DV Policy OID
#2010600 RESOLVED Incident Opened 2026-01-15 · Closed 2026-02-27 · 88% similar
D-Trust: CRLs of CAs issuing CA certificates exceed the maximum validity period
#1691117 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2021-02-05 · Closed 2023-02-22 · 87% similar
D-TRUST: Certificate with RSA key where modulus is not divisible by 8
#1939809 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-01-03 · Closed 2026-06-12 · 87% similar
D-Trust: QCStatement with http link of PKI Disclosure Statements

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action