iTrusChina self-reports CP/CPS inconsistency and TLS certificate misissuance involving clientAuth
iTrusChina opened this case to disclose a compliance incident after being notified by a third-party email on 2026-08-02. The company said its CP/CPS Section 7.1.2 was contradictory about precertificate EKUs versus subscriber certificates, which it described as a violation of TLS BR Section 7.1.2.9. It also reported that it had continued issuing TLS certificates with clientAuth and serverAuth even though its CP/CPS had been updated on 2025-09-19 to allow only serverAuth certificates. iTrusChina said it had stopped new issuance and would revoke the misissued certificates within five days. It also said a full incident report would be provided no later than 2026-08-10.
- iTrusChina updated its CP/CPS to allow only serverAuth certificates.
- iTrusChina was notified by a third-party email about a contradiction in CP/CPS Section 7.1.2.
- iTrusChina disclosed continued issuance of TLS certificates with clientAuth and serverAuth against its CP/CPS and said it had stopped new issuance.
- iTrusChina Co., Ltd. — iTrusChina filed a preliminary incident report describing the CP/CPS inconsistency, the misissuance, the stop on new issuance, and the plan to revoke within five days.