← D-TRUST cases
Bugzilla #2037000 Self Reported Incident Certificate Misissuance Problem Reporting Failure

D-Trust: Missing Pre-Sign Linting for S/MIME Issuing CAs (Section 4.3.1.2)

ASSIGNED D-TRUST
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

D-Trust opened this bug as a self-reported incident after an internal compliance review identified that pre-sign linting required by Section 4.3.1.2 of the S/MIME Baseline Requirements was not implemented for specific S/MIME issuing CAs. The non-compliance period ran from 2025-09-15 to 2026-05-04 09:17 UTC, and D-Trust stated it stopped issuance from the affected part of its PKI at 2026-05-04 09:17 UTC to prevent further non-compliant issuance. D-Trust also migrated issuance to compliant infrastructure. In the full incident report, D-Trust stated that all certificates that were still valid were revoked by 2026-05-08 22:02 UTC, and that the total number of affected certificates was 165,972 with 0 remaining valid. The incident report notes affected issuing CAs and provides a timeline and contributing factor related to lifecycle-transition CAs. The bug remains ASSIGNED, with a later thread update requesting a “Next update” whiteboard date of 2026-07-31 for interim status updates on open action items.

Model: gpt-5.4-nano Generated: 2026-06-13 21:36 UTC Revised: 2026-07-04 18:18 UTC Confidence: 0.86 7 comments
Chronology
  1. Non-compliant S/MIME issuance began due to missing required pre-sign linting (Section 4.3.1.2).
  2. D-Trust identified the missing pre-sign linting and stopped issuance from the affected part of its PKI at 09:17 UTC.
  3. Mass revocation of affected certificates was completed by 22:02 UTC.
  4. The ccadb incident reporting reminder noted the report had gone stale and requested a “Next update” whiteboard field update.
  5. D-Trust requested setting “Next update” to 2026-07-31 for interim status updates on open action items.
Thread Activity
  1. D-Trust — Opened a preliminary incident report stating D-Trust identified missing required pre-sign linting for specific S/MIME issuing CAs, stopped issuance at 09:17 UTC, migrated to compliant infrastructure, and planned revocation of affected certificates.
  2. D-Trust — Confirmed that all revocations were completed in accordance with S/MIME Baseline Requirements timelines and that root cause analysis and follow-up action items would be provided in the full incident report.
  3. D-Trust — Added attachments listing certificate serial numbers of affected certificates.
  4. Bdr representative — Posted the full incident report describing the non-compliant issuance period, affected certificate counts and issuing CAs, and stating issuance was stopped and revocation completed.
  5. CCADB representative — Noted the report had gone stale and reminded that CA Owners may request the “Next update” whiteboard field to be set by a Root Store Operator.
  6. D-Trust — Requested the “Next update” whiteboard field be set to 2026-07-31 and listed current status of open action items.
Participants
D-Trust Bdr representative CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2007116 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Externally Reported Incident Opened 2025-12-19 Still Open · 85% similar
D-Trust: CRL URL Disclosure
#2012511 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2026-01-26 · Closed 2026-04-19 · 84% similar
D-Trust: CRL HTTP Media Type
#2026351 RESOLVED Self Reported Incident Certificate Misissuance Opened 2026-03-25 · Closed 2026-05-18 · 80% similar
Identrust: Root CrossSign, of dedicated Roots, missing EKU
#1979475 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-07-26 · Closed 2026-01-20 · 80% similar
Microsoft PKI Services: End Entity Certificate Mis-issuance against CPS (BasicConstraints)
#2029643 RESOLVED Self Reported Incident Revocation Issue Certificate Misissuance Opened 2026-04-06 · Closed 2026-05-22 · 80% similar
HARICA: Incorrect Open MPIC Lambda implementation by EJBCA ACME Service
#1793440 RESOLVED Self Reported Incident Certificate Misissuance Opened 2022-10-03 · Closed 2023-02-22 · 80% similar
D-TRUST: CRL not DER-encoded
#2005939 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-12-14 · Closed 2026-03-13 · 79% similar
Microsec: CT Logging mistakes
#1756122 RESOLVED Self Reported Incident Certificate Misissuance Opened 2022-02-18 · Closed 2023-02-22 · 79% similar
D-TRUST: Wrong key usage (Key Agreement)

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action