D-Trust: Missing Pre-Sign Linting for S/MIME Issuing CAs (Section 4.3.1.2)
D-Trust opened this bug as a self-reported incident after an internal compliance review identified that pre-sign linting required by Section 4.3.1.2 of the S/MIME Baseline Requirements was not implemented for specific S/MIME issuing CAs. The non-compliance period ran from 2025-09-15 to 2026-05-04 09:17 UTC, and D-Trust stated it stopped issuance from the affected part of its PKI at 2026-05-04 09:17 UTC to prevent further non-compliant issuance. D-Trust also migrated issuance to compliant infrastructure. In the full incident report, D-Trust stated that all certificates that were still valid were revoked by 2026-05-08 22:02 UTC, and that the total number of affected certificates was 165,972 with 0 remaining valid. The incident report notes affected issuing CAs and provides a timeline and contributing factor related to lifecycle-transition CAs. The bug remains ASSIGNED, with a later thread update requesting a “Next update” whiteboard date of 2026-07-31 for interim status updates on open action items.
- Non-compliant S/MIME issuance began due to missing required pre-sign linting (Section 4.3.1.2).
- D-Trust identified the missing pre-sign linting and stopped issuance from the affected part of its PKI at 09:17 UTC.
- Mass revocation of affected certificates was completed by 22:02 UTC.
- The ccadb incident reporting reminder noted the report had gone stale and requested a “Next update” whiteboard field update.
- D-Trust requested setting “Next update” to 2026-07-31 for interim status updates on open action items.
- D-Trust — Opened a preliminary incident report stating D-Trust identified missing required pre-sign linting for specific S/MIME issuing CAs, stopped issuance at 09:17 UTC, migrated to compliant infrastructure, and planned revocation of affected certificates.
- D-Trust — Confirmed that all revocations were completed in accordance with S/MIME Baseline Requirements timelines and that root cause analysis and follow-up action items would be provided in the full incident report.
- D-Trust — Added attachments listing certificate serial numbers of affected certificates.
- Bdr representative — Posted the full incident report describing the non-compliant issuance period, affected certificate counts and issuing CAs, and stating issuance was stopped and revocation completed.
- CCADB representative — Noted the report had gone stale and reminded that CA Owners may request the “Next update” whiteboard field to be set by a Root Store Operator.
- D-Trust — Requested the “Next update” whiteboard field be set to 2026-07-31 and listed current status of open action items.