← D-TRUST cases
Bugzilla #2029013 Revocation Issue

D-Trust: Missing Pre-Signing Linting for TLS Issuance

ASSIGNED D-TRUST
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

D-Trust reported a compliance incident involving its TLS certificate issuance controls under Section 4.3.1.2 of the CA/Browser Forum TLS Baseline Requirements. In its internal review, D-Trust concluded that its RA-side configuration checks did not meet the definition of a “linting tool” for pre-sign linting, and that this preventive control failure allowed non-compliant certificates to reach the CT logs. D-Trust stated that it issued 57,565 certificates in violation of Section 4.3.1.2 over a period from 15 March 2025 to 2 April 2026, and that all affected certificates issued on or after 15 March 2025 were non-compliant. D-Trust stopped issuance from the affected part of its PKI on 2026-04-02 08:45 (UTC), resumed issuance on 2026-04-02 15:40 (UTC) after deploying a compliant pre-sign linting solution, and revoked affected certificates within the next five days. D-Trust confirmed in the thread that all affected TLS certificates had been revoked by 2026-04-07. The bug remains assigned, with a weekly update noting ongoing monitoring and requesting the next update deadline of 2026-08-29.

Model: gpt-5.4-nano Generated: 2026-06-13 21:36 UTC Revised: 2026-06-16 09:59 UTC Confidence: 0.90 9 comments
Chronology
  1. D-Trust began issuing TLS certificates using pre-sign linting controls it later determined were insufficient under TLS Baseline Requirements Section 4.3.1.2.
  2. D-Trust stopped issuance from the affected part of its PKI and later resumed after deploying a compliant pre-sign linting solution.
  3. D-Trust completed revocation of all affected TLS certificates.
Thread Activity
  1. Bdr representative — D-Trust provided a preliminary incident report, stating it stopped issuance on 2026-04-02 08:45 (UTC), resumed on 2026-04-02 15:40 (UTC) after deploying a pre-sign linting solution, and planned revocation within five days.
  2. Bdr representative — D-Trust confirmed that all affected TLS certificates had been revoked.
  3. Heise representative — A bystander asked whether D-Trust had previously simulated mass revocation events as mandated by Mozilla’s Root Store Policy and how.
  4. Bdr representative — D-Trust replied that it conducted mass revocation exercises on 2026-03-03 and 2026-03-24, with the latter performed as part of an independent third-party audit and roles simulated internally.
  5. Bdr representative — D-Trust posted a full incident report stating 57,565 certificates were issued in violation of Section 4.3.1.2 from 2025-03-15 to 2026-04-02 and included a timeline and impact details.
  6. Bdr representative — D-Trust provided a weekly update stating there was nothing new and requested the next update deadline be set for 2026-08-29.
Participants
Bdr representative Heise representative Mozmail representative Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1879529 RESOLVED Revocation Issue Opened 2024-02-09 · Closed 2024-04-06 · 95% similar
D-Trust: "unknown" OCSP response for issued certificates
#1924385 RESOLVED Ca Certificate Compliance Revocation Issue Closure Request Opened 2024-10-13 · Closed 2025-07-16 · 95% similar
D-Trust: Missed Revocation of TLS certificates affected by Bugzilla 1884714
#2037000 ASSIGNED Self Reported Incident Certificate Misissuance Problem Reporting Failure Opened 2026-05-05 Still Open · 83% similar
D-Trust: Missing Pre-Sign Linting for S/MIME Issuing CAs
#1790693 RESOLVED Self Reported Incident Revocation Issue Opened 2022-09-13 · Closed 2023-03-24 · 69% similar
SSL.com: Issuance of 1 EV TLS certificate using a Registration/Incorporation Agency not included in our approved public list.
#1750631 RESOLVED Incident Revocation Issue Opened 2022-01-17 · Closed 2024-06-30 · 68% similar
SSL.com: Issuance of TLS certificates with domain validation methods prohibited by SC-45
#1718771 RESOLVED Self Reported Incident Revocation Issue Opened 2021-06-30 · Closed 2023-02-22 · 68% similar
Sectigo: DCV Reuse after 825 days
#1897346 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-05-17 · Closed 2024-07-24 · 68% similar
SECOM: Difference in upper and lower case between CN field and SAN
#1794047 RESOLVED Revocation Issue Self Reported Incident Opened 2022-10-06 · Closed 2023-02-22 · 68% similar
IdenTrust: Missing Revocation Reasons in CRL

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action