D-Trust: Missing Pre-Signing Linting for TLS Issuance
D-Trust reported a compliance incident involving its TLS certificate issuance controls under Section 4.3.1.2 of the CA/Browser Forum TLS Baseline Requirements. In its internal review, D-Trust concluded that its RA-side configuration checks did not meet the definition of a “linting tool” for pre-sign linting, and that this preventive control failure allowed non-compliant certificates to reach the CT logs. D-Trust stated that it issued 57,565 certificates in violation of Section 4.3.1.2 over a period from 15 March 2025 to 2 April 2026, and that all affected certificates issued on or after 15 March 2025 were non-compliant. D-Trust stopped issuance from the affected part of its PKI on 2026-04-02 08:45 (UTC), resumed issuance on 2026-04-02 15:40 (UTC) after deploying a compliant pre-sign linting solution, and revoked affected certificates within the next five days. D-Trust confirmed in the thread that all affected TLS certificates had been revoked by 2026-04-07. The bug remains assigned, with a weekly update noting ongoing monitoring and requesting the next update deadline of 2026-08-29.
- D-Trust began issuing TLS certificates using pre-sign linting controls it later determined were insufficient under TLS Baseline Requirements Section 4.3.1.2.
- D-Trust stopped issuance from the affected part of its PKI and later resumed after deploying a compliant pre-sign linting solution.
- D-Trust completed revocation of all affected TLS certificates.
- Bdr representative — D-Trust provided a preliminary incident report, stating it stopped issuance on 2026-04-02 08:45 (UTC), resumed on 2026-04-02 15:40 (UTC) after deploying a pre-sign linting solution, and planned revocation within five days.
- Bdr representative — D-Trust confirmed that all affected TLS certificates had been revoked.
- Heise representative — A bystander asked whether D-Trust had previously simulated mass revocation events as mandated by Mozilla’s Root Store Policy and how.
- Bdr representative — D-Trust replied that it conducted mass revocation exercises on 2026-03-03 and 2026-03-24, with the latter performed as part of an independent third-party audit and roles simulated internally.
- Bdr representative — D-Trust posted a full incident report stating 57,565 certificates were issued in violation of Section 4.3.1.2 from 2025-03-15 to 2026-04-02 and included a timeline and impact details.
- Bdr representative — D-Trust provided a weekly update stating there was nothing new and requested the next update deadline be set for 2026-08-29.