Closed Bug 2016267 Opened 7 months ago Closed 4 months ago

IdenTrust: Gap between audit periods

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: roots, Assigned: roots)

Details

(Whiteboard: [ca-compliance] [audit-failure])

Attachments

(2 files)

User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36

Steps to reproduce:

Preliminary Incident Report

Summary

  • Incident Description
    During a TLS single-purpose root inclusion request with Chrome, we are being made aware that one root certificate has an 81-day gap in audit coverage.

Relevant policies:

  • TLS BR Section 8.1
  • Chrome Root Program v1.8 Section 1.1.4
  • Chrome Root Policy Mozilla Root Store Policy v3.0 Section 3.1.3
    The policies above require that that CAs issuing publicly trusted certificates must maintain a continuous, unbroken sequence of annual audits under an approved scheme (e.g., WebTrust for CAs or ETSI EN 319 411).

Source of incident disclosure:
Third party reported

Impact

The root in question did not issue any additional certificates during the 81-day audit gap. We have initiated a remediation plan with our external audit firm to issue an updated WebTrust audit report that includes the root for the period in which this root was excluded.

A full incident report will be disclosed by February 25, 2026.

Assignee: nobody → roots
Status: UNCONFIRMED → ASSIGNED
Type: defect → task
Ever confirmed: true
Whiteboard: [ca-compliance] [audit-failure]

Full Incident Report

Summary

  • CA Owner CCADB unique ID: A000036
  • Incident description:
    • During a TLS single-purpose root inclusion request with Chrome, we are made aware that one root certificate has an 81-day gap in audit coverage. We reviewed the notes gap and confined that Commercial Root TLS ECC CA 2 was not included in the 2023/2024 WebTrust audit report.
    • We have engaged the Qualified Auditor who conducted both the root generation witnessing and the annual WebTrust for CA audit for 2023–2024. The auditors confirm they will generate an updated WebTrust audit report to reflect an end date of 2024.
    • The outcome will be an updated WebTrust report that properly includes the root that has been within the audit scope since the 2024 audit.
  • Timeline summary:
    • Non-compliance start date: 2024-08-24
    • Non-compliance identified date: 2026-02-09
  • Relevant policies:
    • TLS BR Section 8.1
    • Chrome Root Program v1.8 Section 1.1.4
    • Chrome Root Policy Mozilla Root Store Policy v3.0 Section 3.1.3
      The policies above require that CAs issuing publicly trusted certificates must maintain a continuous, unbroken sequence of annual audits under an approved scheme (e.g., WebTrust for CAs or ETSI EN 319 411).
  • Source of incident disclosure:
    Third party reported

Impact

Commercial Root TLS ECC CA 2 was not included in the 2023/2024 WebTrust audit report which created a broken sequence of annual audit for Commercial Root TLS ECC CA 2.

Related Incidents

We were not able to find relevant incidents.

Root Cause Analysis

Root Cause # 1

  • There was confusion between IdenTrust and the auditors about whether Commercial Root TLS ECC CA 2 should be included in the audit report. Although the root had already been added to the CCADB, it was not yet in production during the audit period.
  • As a result of this misunderstanding, Commercial Root TLS ECC CA 2 was not included in the 2023/2024 WebTrust audit report.

Lessons Learned

  • What went well:
    No customer certificate was impacted.
  • What didn’t go well:
    Broken sequence of annual audits.
  • Where we got lucky:
    The root in question did not issue any customer certificates during the 81-day audit gap.

Action Items

Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status
Update WebTrust audit report Correct Root Cause # 1 Updated 2024 WebTrust report 2026-03-31 Pending

Appendix

Audit report, from Schellman, with missing ICA (Updated Mar 3rd 2026). This covers the 81 day gap that was unaccounted for. (Identrust Commercial Root TLS ECC CA 2)

Our team identified some discrepancies in the updated audit report, we attached here
https://bugzilla.mozilla.org/attachment.cgi?id=9550433

The prior approved draft sent to us by the auditor was correct, but the final sent to us, is missing details in the "IdenTrust's Root and Issuing CAs" table. We're working with the auditor to correct this. Once corrected we'll get the corrected version attached.

Audit report, from Schellman, with missing CAs (Updated Mar 3rd 2026). This covers the 81 day gap that was unaccounted for:

  • Identrust Commercial Root TLS ECC CA 2
  • Identrust Commercial Root SMIME ECC CA 2
  • Identrust Commercial Root Client-Auth ECC CA 2
  • Identrust Commercial Root Timestamp ECC CA 2

For the action item:
"Update WebTrust audit report"

We received the updated version of the Webtrust audit report.
Attached here

We'll work this next week, to get this document added in CCADB to audit documents, for relevant CAs.

The updated, Webtrust audit report was updated in CCADB here:
A07287

Report Closure Summary

  • Incident description:
  • During a TLS single-purpose root inclusion request with Chrome, we are made aware that one root certificate has an 81-day gap in audit coverage. We reviewed the notes gap and confined that Commercial Root TLS ECC CA 2 was not included in the 2023/2024 WebTrust audit report.
  • We have engaged the Qualified Auditor who conducted both the root generation witnessing and the annual WebTrust for CA audit for 2023–2024. The auditors confirm they will generate an updated WebTrust audit report to reflect an end date of 2024.
  • Incident Root Cause(s):
  • There was confusion between IdenTrust and the auditors about whether Commercial Root TLS ECC CA 2 should be included in the audit report. Although the root had already been added to the CCADB, it was not yet in production during the audit period.
  • As a result of this misunderstanding, Commercial Root TLS ECC CA 2 was not included in the 2023/2024 WebTrust audit report.
  • Remediation description:
    -Updated WebTrust report was returned from auditor, and now properly includes the root that had been ommitted from the 2024 audit (July 1 2023 - June 30, 2024).
    https://bugzilla.mozilla.org/attachment.cgi?id=9552920
  • Commitment summary:
    Commited action items are now complete:
    Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status
    Update WebTrust audit report Correct Root Cause # 1 Updated 2024 WebTrust report 2026-03-19 Complete

The audit report is now available in CCADB, to reflect Identrust's CAs correctly.

Appendix

All Action Items disclosed in this report have been completed as described, and we request its closure.

Please let us know if there is anything additional we can provide, in addition to the closure report.

Flags: needinfo?(incident-reporting)

(In reply to IdenTrust from comment #6)

The updated, Webtrust audit report was updated in CCADB here:
A07287

Report Closure Summary

  • Incident description:
  • During a TLS single-purpose root inclusion request with Chrome, we are made aware that one root certificate has an 81-day gap in audit coverage. We reviewed the notes gap and confined that Commercial Root TLS ECC CA 2 was not included in the 2023/2024 WebTrust audit report.
  • We have engaged the Qualified Auditor who conducted both the root generation witnessing and the annual WebTrust for CA audit for 2023–2024. The auditors confirm they will generate an updated WebTrust audit report to reflect an end date of 2024.
  • Incident Root Cause(s):
  • There was confusion between IdenTrust and the auditors about whether Commercial Root TLS ECC CA 2 should be included in the audit report. Although the root had already been added to the CCADB, it was not yet in production during the audit period.
  • As a result of this misunderstanding, Commercial Root TLS ECC CA 2 was not included in the 2023/2024 WebTrust audit report.
  • Remediation description:
    -Updated WebTrust report was returned from auditor, and now properly includes the root that had been ommitted from the 2024 audit (July 1 2023 - June 30, 2024).
    https://bugzilla.mozilla.org/attachment.cgi?id=9552920
  • Commitment summary:
    Commited action items are now complete:
    Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status
    Update WebTrust audit report Correct Root Cause # 1 Updated 2024 WebTrust report 2026-03-19 Complete

The audit report is now available in CCADB, to reflect Identrust's CAs correctly.

Appendix

All Action Items disclosed in this report have been completed as described, and we request its closure.

We had submitted the final closure report, but we are waiting for the call for final comments.

Flags: needinfo?(incident-reporting)

Please let us know if there is anything else we can provide.

Flags: needinfo?(incident-reporting)

This is a final call for comments or questions on this Incident Report.

Otherwise, it will be closed on approximately 2026-04-15.

Whiteboard: [ca-compliance] [audit-failure] → [close on 2026-04-15] [ca-compliance] [audit-failure]
Status: ASSIGNED → RESOLVED
Closed: 4 months ago
Flags: needinfo?(incident-reporting)
Resolution: --- → FIXED
Whiteboard: [close on 2026-04-15] [ca-compliance] [audit-failure] → [ca-compliance] [audit-failure]
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: