IdenTrust: Gap between audit periods
Categories
(CA Program :: CA Certificate Compliance, task)
Tracking
(Not tracked)
People
(Reporter: roots, Assigned: roots)
Details
(Whiteboard: [ca-compliance] [audit-failure])
Attachments
(2 files)
User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Steps to reproduce:
Preliminary Incident Report
Summary
- Incident Description
During a TLS single-purpose root inclusion request with Chrome, we are being made aware that one root certificate has an 81-day gap in audit coverage.
Relevant policies:
- TLS BR Section 8.1
- Chrome Root Program v1.8 Section 1.1.4
- Chrome Root Policy Mozilla Root Store Policy v3.0 Section 3.1.3
The policies above require that that CAs issuing publicly trusted certificates must maintain a continuous, unbroken sequence of annual audits under an approved scheme (e.g., WebTrust for CAs or ETSI EN 319 411).
Source of incident disclosure:
Third party reported
Impact
The root in question did not issue any additional certificates during the 81-day audit gap. We have initiated a remediation plan with our external audit firm to issue an updated WebTrust audit report that includes the root for the period in which this root was excluded.
A full incident report will be disclosed by February 25, 2026.
Updated•7 months ago
|
Full Incident Report
Summary
- CA Owner CCADB unique ID: A000036
- Incident description:
- During a TLS single-purpose root inclusion request with Chrome, we are made aware that one root certificate has an 81-day gap in audit coverage. We reviewed the notes gap and confined that Commercial Root TLS ECC CA 2 was not included in the 2023/2024 WebTrust audit report.
- We have engaged the Qualified Auditor who conducted both the root generation witnessing and the annual WebTrust for CA audit for 2023–2024. The auditors confirm they will generate an updated WebTrust audit report to reflect an end date of 2024.
- The outcome will be an updated WebTrust report that properly includes the root that has been within the audit scope since the 2024 audit.
- Timeline summary:
- Non-compliance start date: 2024-08-24
- Non-compliance identified date: 2026-02-09
- Relevant policies:
- TLS BR Section 8.1
- Chrome Root Program v1.8 Section 1.1.4
- Chrome Root Policy Mozilla Root Store Policy v3.0 Section 3.1.3
The policies above require that CAs issuing publicly trusted certificates must maintain a continuous, unbroken sequence of annual audits under an approved scheme (e.g., WebTrust for CAs or ETSI EN 319 411).
- Source of incident disclosure:
Third party reported
Impact
Commercial Root TLS ECC CA 2 was not included in the 2023/2024 WebTrust audit report which created a broken sequence of annual audit for Commercial Root TLS ECC CA 2.
Related Incidents
We were not able to find relevant incidents.
Root Cause Analysis
Root Cause # 1
- There was confusion between IdenTrust and the auditors about whether Commercial Root TLS ECC CA 2 should be included in the audit report. Although the root had already been added to the CCADB, it was not yet in production during the audit period.
- As a result of this misunderstanding, Commercial Root TLS ECC CA 2 was not included in the 2023/2024 WebTrust audit report.
Lessons Learned
- What went well:
No customer certificate was impacted. - What didn’t go well:
Broken sequence of annual audits. - Where we got lucky:
The root in question did not issue any customer certificates during the 81-day audit gap.
Action Items
| Action Item | Kind | Corresponding Root Cause(s) | Evaluation Criteria | Due Date | Status |
|---|---|---|---|---|---|
| Update WebTrust audit report | Correct | Root Cause # 1 | Updated 2024 WebTrust report | 2026-03-31 | Pending |
Appendix
Audit report, from Schellman, with missing ICA (Updated Mar 3rd 2026). This covers the 81 day gap that was unaccounted for. (Identrust Commercial Root TLS ECC CA 2)
Our team identified some discrepancies in the updated audit report, we attached here
https://bugzilla.mozilla.org/attachment.cgi?id=9550433
The prior approved draft sent to us by the auditor was correct, but the final sent to us, is missing details in the "IdenTrust's Root and Issuing CAs" table. We're working with the auditor to correct this. Once corrected we'll get the corrected version attached.
Audit report, from Schellman, with missing CAs (Updated Mar 3rd 2026). This covers the 81 day gap that was unaccounted for:
- Identrust Commercial Root TLS ECC CA 2
- Identrust Commercial Root SMIME ECC CA 2
- Identrust Commercial Root Client-Auth ECC CA 2
- Identrust Commercial Root Timestamp ECC CA 2
For the action item:
"Update WebTrust audit report"
We received the updated version of the Webtrust audit report.
Attached here
We'll work this next week, to get this document added in CCADB to audit documents, for relevant CAs.
The updated, Webtrust audit report was updated in CCADB here:
A07287
Report Closure Summary
- Incident description:
- During a TLS single-purpose root inclusion request with Chrome, we are made aware that one root certificate has an 81-day gap in audit coverage. We reviewed the notes gap and confined that Commercial Root TLS ECC CA 2 was not included in the 2023/2024 WebTrust audit report.
- We have engaged the Qualified Auditor who conducted both the root generation witnessing and the annual WebTrust for CA audit for 2023–2024. The auditors confirm they will generate an updated WebTrust audit report to reflect an end date of 2024.
- Incident Root Cause(s):
- There was confusion between IdenTrust and the auditors about whether Commercial Root TLS ECC CA 2 should be included in the audit report. Although the root had already been added to the CCADB, it was not yet in production during the audit period.
- As a result of this misunderstanding, Commercial Root TLS ECC CA 2 was not included in the 2023/2024 WebTrust audit report.
- Remediation description:
-Updated WebTrust report was returned from auditor, and now properly includes the root that had been ommitted from the 2024 audit (July 1 2023 - June 30, 2024).
https://bugzilla.mozilla.org/attachment.cgi?id=9552920 - Commitment summary:
Commited action items are now complete:Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status Update WebTrust audit report Correct Root Cause # 1 Updated 2024 WebTrust report 2026-03-19 Complete
The audit report is now available in CCADB, to reflect Identrust's CAs correctly.
Appendix
All Action Items disclosed in this report have been completed as described, and we request its closure.
Please let us know if there is anything additional we can provide, in addition to the closure report.
(In reply to IdenTrust from comment #6)
The updated, Webtrust audit report was updated in CCADB here:
A07287Report Closure Summary
- Incident description:
- During a TLS single-purpose root inclusion request with Chrome, we are made aware that one root certificate has an 81-day gap in audit coverage. We reviewed the notes gap and confined that Commercial Root TLS ECC CA 2 was not included in the 2023/2024 WebTrust audit report.
- We have engaged the Qualified Auditor who conducted both the root generation witnessing and the annual WebTrust for CA audit for 2023–2024. The auditors confirm they will generate an updated WebTrust audit report to reflect an end date of 2024.
- Incident Root Cause(s):
- There was confusion between IdenTrust and the auditors about whether Commercial Root TLS ECC CA 2 should be included in the audit report. Although the root had already been added to the CCADB, it was not yet in production during the audit period.
- As a result of this misunderstanding, Commercial Root TLS ECC CA 2 was not included in the 2023/2024 WebTrust audit report.
- Remediation description:
-Updated WebTrust report was returned from auditor, and now properly includes the root that had been ommitted from the 2024 audit (July 1 2023 - June 30, 2024).
https://bugzilla.mozilla.org/attachment.cgi?id=9552920- Commitment summary:
Commited action items are now complete:
Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status Update WebTrust audit report Correct Root Cause # 1 Updated 2024 WebTrust report 2026-03-19 Complete The audit report is now available in CCADB, to reflect Identrust's CAs correctly.
Appendix
All Action Items disclosed in this report have been completed as described, and we request its closure.
We had submitted the final closure report, but we are waiting for the call for final comments.
Please let us know if there is anything else we can provide.
Comment 10•5 months ago
|
||
This is a final call for comments or questions on this Incident Report.
Otherwise, it will be closed on approximately 2026-04-15.
Updated•4 months ago
|
Description
•