D-Trust self-disclosed TLS issuance control failure involving missing pre-sign linting
D-Trust reported a self-disclosed compliance incident involving its TLS issuance controls under CA/Browser Forum TLS Baseline Requirements Section 4.3.1.2. The company said its RA-side and CA-side pre-sign checks did not meet the intended linting requirement, which allowed non-compliant TLS certificates to be issued and logged. D-Trust stopped issuance from the affected part of its PKI on 2026-04-02 and resumed after deploying a compliant pre-sign linting solution. In its full incident report, D-Trust said 57,565 certificates were issued non-compliantly between 2025-03-15 and 2026-04-02, affecting DV, OV, and EV TLS certificates. D-Trust confirmed that all affected certificates had been revoked by 2026-04-07. The thread later shifted to follow-up discussion about mass revocation exercises and browser revocation handling, and D-Trust’s latest update said the remaining action item was still ongoing with a due date of 2026-09-30.
- D-Trust continued issuing TLS certificates after the mandatory pre-sign linting requirement in Section 4.3.1.2 took effect.
- D-Trust stopped issuance from the affected part of its PKI and later resumed after deploying a compliant pre-sign linting solution.
- D-Trust completed revocation of all affected TLS certificates.
- Bdr representative — D-Trust filed a preliminary incident report saying its internal checks did not satisfy the linting requirement and that it had stopped issuance pending remediation.
- Bdr representative — D-Trust confirmed that all affected TLS certificates had been revoked.
- Bdr representative — D-Trust said it had conducted mass revocation exercises on 2026-03-03 and 2026-03-24, with the latter performed as part of an independent third-party audit.
- Bdr representative — D-Trust posted a full incident report stating that 57,565 certificates were issued in violation of Section 4.3.1.2 and that the affected certificates had been revoked.
- Mozilla representative — Mozilla explained that CA revocation obligations and browser revocation enforcement are separate, and that browser vendors may respond more aggressively in active security threats.
- Bdr representative — D-Trust provided a weekly update saying there was nothing new to report and requested the next update deadline be set for 2026-08-29.
- D-Trust — D-Trust said the remaining action item was ongoing, the previously reported due date of 2026-09-30 was unchanged, and requested the next update date be set to 2026-09-30.