← iTrusChina Co., Ltd. cases
Bugzilla #2060152 Ca Certificate Compliance Self Reported Incident Certificate Misissuance Policy Document Issue Revocation Issue

iTrusChina self-reports CP/CPS inconsistency and TLS certificate misissuance involving clientAuth

ASSIGNED iTrusChina Co., Ltd.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

iTrusChina opened this bug to disclose a compliance incident after a third-party email on 2026-08-02 pointed out a contradiction in Section 7.1.2 of its CP/CPS. The company said the inconsistency affected the EKU description for precertificates versus subscriber certificates and was a violation of TLS BR Section 7.1.2.9. It also found that it had continued issuing TLS certificates with clientAuth and serverAuth after its CP/CPS update on 2025-09-19 allowed only serverAuth in subscriber certificates. iTrusChina said it stopped new issuance, updated the certificate profiles and CP/CPS, and revoked all misissued certificates within five days. The latest thread activity says all action items have been finished and that iTrusChina is monitoring the bug for further comments or questions.

Model: gpt-5.4-mini Generated: 2026-08-04 07:22 UTC Revised: 2026-09-13 08:00 UTC Confidence: 0.98 6 comments
Chronology
  1. iTrusChina updated its CP/CPS to allow only serverAuth certificates.
  2. iTrusChina received a third-party CPR about a CP/CPS EKU inconsistency.
  3. iTrusChina confirmed the CP/CPS inconsistency and the continued issuance of clientAuth and serverAuth TLS certificates.
  4. iTrusChina revoked all misissued certificates within five days.
  5. iTrusChina said all action items had been finished.
Thread Activity
  1. iTrusChina Co., Ltd. — iTrusChina filed a preliminary incident report describing the CP/CPS inconsistency, the misissuance, the stop on new issuance, and the plan to revoke within five days.
  2. iTrusChina Co., Ltd. — iTrusChina posted the full incident report with impact, timeline, remediation steps, and confirmation that all misissuances were revoked.
  3. iTrusChina Co., Ltd. — iTrusChina said it was monitoring the bug and that all action items had been completed.
  4. iTrusChina Co., Ltd. — iTrusChina reiterated that it was monitoring the bug for comments and questions.
  5. iTrusChina Co., Ltd. — iTrusChina again said it was monitoring the bug for comments and questions.
  6. iTrusChina Co., Ltd. — iTrusChina said it was monitoring the bug for comments and questions and would provide more information if needed.
Participants
iTrusChina Co., Ltd.
Related Bugzilla IDs Mentioned
Similar Local Cases
#2013805 RESOLVED Ca Certificate Compliance Opened 2026-02-02 · Closed 2026-05-01 · 77% similar
iTrusChina: Finding in Routine WebTrust Audit - Domain validation records without the TLS BR version
#2025248 RESOLVED Self Reported Incident Opened 2026-03-23 · Closed 2026-05-01 · 77% similar
iTrusChina: Failure to Provide Regular Incident Update
#2020899 RESOLVED Self Reported Incident Opened 2026-03-04 · Closed 2026-04-11 · 76% similar
iTrusChina: Failure to Respond to Feb 2026 Chrome Root Program Survey
#1712664 RESOLVED Ca Certificate Compliance Opened 2021-05-25 · Closed 2023-02-22 · 75% similar
iTrusChina: verification errors for the roots' CRLs(ARL)
#1927384 RESOLVED Certificate Misissuance Opened 2024-10-28 · Closed 2025-01-29 · 75% similar
iTrusChina: Issuance of certificates using keys previously reported as compromised
#2037000 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-05-05 Still Open · 73% similar
D-Trust: Missing Pre-Sign Linting for S/MIME Issuing CAs
#2066864 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-08-26 Still Open · 72% similar
eMudhra emSign PKI Services: Test Website TLS Certificates Issued Against CP/CPS.
#2057520 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-07-24 Still Open · 72% similar
eMudhra emSign PKI Services: Invalid Subject Locality/State Values

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action