← D-TRUST cases
Bugzilla #2037000
Certificate Problem Report
D-Trust: Missing Pre-Sign Linting for S/MIME Issuing CAs
ASSIGNED
D-TRUST
AI Summary
D-Trust reported a compliance issue regarding the lack of pre-sign linting for S/MIME issuing CAs, which violated Section 4.3.1.2 of the S/MIME Baseline Requirements. The non-compliance was identified on May 4, 2026, leading to the cessation of certificate issuance from affected CAs and the revocation of 165,972 certificates. The incident was self-reported as part of an internal compliance review following a previous Bugzilla incident. D-Trust has since migrated to compliant infrastructure and completed all necessary revocations.
Chronology
- Non-compliance period began
- Non-compliance identified and issuance stopped
- Mass revocation of certificates completed
Participants
Ana Laura Martorano
Frank Meissen
External References
Similar Local Cases
D-Trust: CRL HTTP Media Type
D-Trust: Defective certificate incident reporting form
D-Trust: Expired certificate provided on the CA TLS test website for demonstration of valid certificates
D-Trust: CRL URL Disclosure
D-Trust: TLS Precertificates Exceeding the Maximum Validity Period Allowed by the TLS Baseline Requirements
D-Trust: CRLs of CAs issuing CA certificates exceed the maximum validity period
D-Trust: Missing Pre-Signing Linting for TLS Issuance
D-TRUST: incorrectly formatted businessCategory entry