← D-TRUST cases
Bugzilla #2037000 Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Audit Document

D-Trust S/MIME pre-sign linting incident: action items #2 and #3 completed, others still open

ASSIGNED D-TRUST
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

D-Trust self-reported that it had issued S/MIME certificates in violation of Section 4.3.1.2 of the S/MIME Baseline Requirements because required pre-sign linting was not implemented for specific S/MIME issuing CAs. The issue was identified internally on 2026-05-04, issuance from the affected part of the PKI was stopped the same day, and issuance was migrated to compliant infrastructure. D-Trust reported that all certificates still valid at the time were revoked by 2026-05-08 22:02 UTC. The bug has continued to track follow-up action items after the incident report was filed. In the latest update on 2026-08-28, D-Trust said Action Items #2 and #3 were complete, while Action Items #1, #4, and #5 remained open. D-Trust requested that the next update whiteboard field be set to 2026-09-30.

Model: gpt-5.4-mini Generated: 2026-06-13 21:36 UTC Revised: 2026-08-30 06:00 UTC Confidence: 0.98 12 comments
Chronology
  1. Non-compliant S/MIME issuance began because required pre-sign linting was not implemented for the affected issuing CAs.
  2. D-Trust identified the missing pre-sign linting and stopped issuance from the affected part of its PKI.
  3. All remaining valid affected certificates were revoked.
  4. D-Trust reported that Action Items #2 and #3 were complete and that Action Items #1, #4, and #5 remained open.
Thread Activity
  1. D-Trust — Posted a preliminary incident report describing the missing pre-sign linting, the stop to issuance, and the plan to revoke affected certificates.
  2. D-Trust — Confirmed that all revocations were completed within the required timelines and said root cause analysis and follow-up action items would follow.
  3. Bdr representative — Posted the full incident report with the non-compliance period, affected certificate count, affected issuing CAs, and completion of revocation.
  4. CCADB representative — Noted that the report had gone stale and reminded the CA owner about the Next update whiteboard field.
  5. D-Trust — Requested that the Next update whiteboard field be set to 2026-07-31 and listed the status of open action items.
  6. D-Trust — Reported that Action Item #4 was still ongoing and under audit.
  7. D-Trust — Said there was nothing new to report and that D-Trust continued working on the action items.
  8. D-Trust — Repeated that there was nothing new to report and that the action items were still ongoing.
  9. D-Trust — Said the agreed action items were still being implemented and that an update would follow once all actions were completed.
  10. D-Trust — Reported completion of Action Items #2 and #3, said Action Items #1, #4, and #5 remained open, and requested the next update whiteboard field be set to 2026-09-30.
Participants
D-Trust Bdr representative CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2007116 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Ccadb Disclosure Issue Opened 2025-12-19 · Closed 2026-09-03 · 100% similar
D-Trust: CRL URL Disclosure
#2056223 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-07-20 · Closed 2026-08-08 · 97% similar
D-Trust OCSP Responder Certificates Include CA/B Forum DV Policy OID
#2012511 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2026-01-26 · Closed 2026-04-19 · 94% similar
D-Trust: CRL HTTP Media Type
#2029013 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Validation Issue Opened 2026-04-02 Still Open · 94% similar
D-Trust: Missing Pre-Signing Linting for TLS Issuance
#2010600 RESOLVED Incident Opened 2026-01-15 · Closed 2026-02-27 · 88% similar
D-Trust: CRLs of CAs issuing CA certificates exceed the maximum validity period
#2023458 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-03-15 · Closed 2026-07-31 · 88% similar
D-Trust: TLS Precertificates Exceeding the Maximum Validity Period Allowed by the TLS Baseline Requirements
#1976837 RESOLVED Incident Opened 2025-07-11 · Closed 2025-08-19 · 85% similar
D-Trust: Defective certificate incident reporting form
#2009149 RESOLVED Incident Opened 2026-01-08 · Closed 2026-08-05 · 85% similar
D-Trust: Expired certificate provided on the CA TLS test website for demonstration of valid certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action