IdenTrust: End Entity TLS certificate mis-issuance against CP/CPS (IdenTrust certificate policy OIDs)
Categories
(CA Program :: CA Certificate Compliance, task)
Tracking
(Not tracked)
People
(Reporter: roots, Assigned: roots)
Details
(Whiteboard: [ca-compliance] [dv-misissuance] [ov-misissuance] [ev-misissuance])
Attachments
(1 file)
|
1.02 MB,
application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
|
Details |
Preliminary Incident Report
Summary
- Incident description: An internal review of IdenTrust’s TrustID TLS CP/CPS identified a compliance issue involving issuance of the TLS end-entity certificates. TLS certificates were issued with additional IdenTrust certificate policy OIDs. Our CP/CPS had a date for removal of inclusion of those certificate policy OIDs.
Upon confirmation, issuance was halted and resumed after remediation was completed. All impacted certificates will be revoked within 5 days. - Relevant policies: TrustID TLS CP/CPS v5.0.3 Section 7.1.2.3 and Section 7.1.6.
- Source of incident disclosure: Self-reported (Internal review of TLS CP/CPS).
Updated•3 months ago
|
Weekly Status Update
We are actively working on the full incident report and will have it posted no later than 6/30.
Full Incident Report
Summary
- CA Owner CCADB unique ID: A000036
- Incident description:
IdenTrust identified a compliance issue involving the issuance of TLS end-entity certificates that did not conform with our TLS CP/CPS version 5.0.3. On 2026-06-16 we discovered that 42858 TLS certificates were issued with the certificatePolicies extension asserting both CA/B Forum and IdenTrust’s certificate policy identifiers. While the BRs and root programs do not limit inclusion of Issuing CAs certificate policy IDs, our TLS CP/CPS had a deadline of 2026-06-15 to no longer include IdenTrust’s certificate policy IDs. Therefore, these certificates were non-compliant with our TLS CP/CPS when they were issued. There were no security concerns with the issued certificates.
This incident triggered our mass revocation plan. All impacted certificates are disclosed in the attachment and were revoked by 2026-06-20.
- Timeline summary:
- Non-compliance start date: 2026-06-16 00:00 UTC
- Non-compliance identified date: 2026-06-16 18:11 UTC
- Non-compliance end date: 2026-06-16 19:47 UTC
- Relevant policies: TrustID TLS CP/CPS v5.0.3 Section 7.1.2.3 and Section 7.1.6, TLS BRs Section 7.1.2.7.9, and EV Guidelines Section 7.1.6.4.
- Source of incident disclosure: Self-reported (Internal review of TLS CP/CPS).
Impact
- Total number of certificates: 42858
- Total number of "remaining valid" certificates: 42858
- Affected certificate types: TLS end-entity certificates (DV, OV, and EV)
- Incident heuristic: The full corpus of affected certificates are disclosed in the attachment.
- Was issuance stopped in response to this incident, and why or why not?: Yes, the issue was a non-compliance with our CP/CPS.
- Analysis: N/A. All affected certificates were revoked as part of the incident.
- Additional considerations: N/A
Timeline
All times are UTC unless otherwise noted.
- 2025-10-24 - Draft version of Chrome’s Root Program Policy v1.8 shared date
- 2026-01-26 - Updates addressing draft root program policy OID restrictions made to TrustID TLS CP/CPS
- 2026-02-05 - Chrome’s Root Program Policy v1.8 published date
- 2026-03-19 - TrustID TLS CP/CPS v5.0.3 published date
- 2026-06-16 00:00 - Non-compliance start date
- 2026-06-16 17:03 - Internal investigation of the incident began
- 2026-06-16 18:11 - Non-compliance confirmation
- 2026-06-16 18:58 - Issuance paused
- 2026-06-16 19:47 - Non-compliance end date with TLS CP/CPS v5.0.4 published
- 2026-06-20 23:16 - Impacted certificates revocation complete
Related Incidents
| Bug | Date | Description |
|---|---|---|
| 2011865 | 2026-01-22 | SSL DV Mis-issuance against CP/CPS (IPAddress) |
| 1981680 | 2025-08-07 | SSL OV mis-issuance against CP/CPS (Email attribute) |
| 1979475 | 2025-07-25 | End Entity Certificate Mis-issuance against CPS (BasicConstraints) |
Root Cause Analysis
Contributing Factor #1: CP/CPS future timeline based on draft policy
- Description:
A draft version of Chrome’s Root Program Policy v1.8 included a requirement that the certificatePolicies extension only assert the appropriate CA/B Forum reserved policy OIDs. IdenTrust proactively included a deadline of 2026-06-15, to no longer issue TLS certificates with IdenTrust’s certificate policy IDs within Section 7 of our TLS CP/CPS to follow the draft root program policy requirement. This restriction was not reexamined after Chrome’s Root Program Policy v1.8 was finalized and published, in which that requirement had been removed. Therefore, this restriction remained in place in our documentation when we published version 5.0.3 of the TLS CP/CPS on 2026-03-09. - Timeline:
- 2025-10-24 - Draft version of Chrome’s Root Program Policy v1.8 shared date
- 2026-01-26 - Updates addressing draft root program policy OID restrictions made to TrustID TLS CP/CPS
- 2026-02-05 - Chrome’s Root Program Policy v1.8 published date
- 2026-03-19 - TrustID TLS CP/CPS v5.0.3 published date
- 2026-06-16 00:00 UTC - Non-compliance start date
- Detection: An internal review noted a CP/CPS update due to a draft root program policy.
- Interaction with other factors: N/A
- Root Cause Analysis methodology used: 5-Whys
Lessons Learned
- What went well:
- The investigation quickly found the cause of the non-compliance which allowed prompt discussion on remediation plans.
- The previously performed tabletop exercise for the mass revocation plan provided the team a higher level of comfort in executing the process.
- The quick pause of issuance prevented additional mis-issuance and prevented impacting more end-users.
- What didn’t go well:
- A comparison of modifications from the draft root program policy version to the final root program policy version would have helped catch the self-imposed deadline.
- Where we got lucky:
- The issue was flagged shortly after non-compliance which helped minimize the scope of the certificates affected.
- The remediation required only a few modifications in the TLS CP/CPS which took minimal time to update, review, and approve before publishing.
- Additional: None
Action Items
| Action Item | Kind | Corresponding Root Cause(s) | Evaluation Criteria | Due Date | Status |
|---|---|---|---|---|---|
| CP/CPS updated | Mitigate | Root Cause #1 | Removal of self-imposed deadline | 2026-06-16 | Complete |
| Revoke impacted certificates | Mitigate | Root Cause #1 | Status of all impacted certificates is “Revoked” | 2026-06-20 | Complete |
| Place deadlines tied to draft policies in a separate branch CP/CPS that will be merged if and only if the final deadlines are confirmed. | Prevent | Root Cause #1 | Changes incorporated into the process verified by Policy Management Authority Board | 2026-07-10 | Ongoing |
Appendix
See attached file for list of affected certificates.
The following action items, are still being worked on, and are expected to complete on time:
Action Items
| Action Item | Kind | Corresponding Root Cause(s) | Evaluation Criteria | Due Date | Status |
|---|---|---|---|---|---|
| Place deadlines tied to draft policies in a separate branch CP/CPS that will be merged if and only if the final deadlines are confirmed. | Prevent | Root Cause #1 | Changes incorporated into the process verified by Policy Management Authority Board | 2026-07-10 | Ongoing |
The following action items are complete.
Action Items
| Action Item | Kind | Corresponding Root Cause(s) | Evaluation Criteria | Due Date | Status |
|---|---|---|---|---|---|
| Place deadlines tied to draft policies in a separate branch CP/CPS that will be merged if and only if the final deadlines are confirmed. | Prevent | Root Cause #1 | Changes incorporated into the process verified by Policy Management Authority Board | 2026-07-10 | Complete |
Report Closure Summary
-
Incident description:
IdenTrust identified a compliance issue involving the issuance of TLS end-entity certificates that did not conform with our TLS CP/CPS version 5.0.3. On 2026-06-16 we discovered that 42858 TLS certificates were issued with the certificatePolicies extension asserting both CA/B Forum and IdenTrust’s certificate policy identifiers. While the BRs and root programs do not limit inclusion of Issuing CAs certificate policy IDs, our TLS CP/CPS had a deadline of 2026-06-15 to no longer include IdenTrust’s certificate policy IDs. Therefore, these certificates were non-compliant with our TLS CP/CPS when they were issued. There were no security concerns with the issued certificates.
This incident triggered our mass revocation plan. All impacted certificates are disclosed in the attachment and were revoked by 2026-06-20. -
Incident Root Cause(s):
IdenTrust proactively included a deadline, to no longer issue TLS certificates with IdenTrust’s certificate policy IDs within Section 7 of our TLS CP/CPS to follow the draft Chrome Root Program Policy v1.8 requirement that the certificatePolicies extension only assert the appropriate CA/B Forum reserved policy OIDs. This restriction was not reexamined after Chrome’s Root Program Policy v1.8 was finalized and published, in which that requirement had been removed, and this restriction remained in place in our TLS CP/CPS when we published version 5.0.3. -
Remediation description:
IdenTrust’s TLS CP/CPS was updated to remove the self-imposed deadline. The affected certificates were revoked in alignment with the CA/B Forum TLS Baseline Requirements. Process improvements to the CP/CPS generation were applied to prevent approval of CP/CPSs that included draft root program policies. -
Commitment summary:
IdenTrust will continue to be proactive in addressing upcoming policy updates.
All Action Items disclosed in this report have been completed as described, and we request its closure.
Comment 7•2 months ago
|
||
This is a final call for comments or questions on this Incident Report.
Otherwise, it will be closed on approximately 2026-08-03.
Updated•2 months ago
|
Updated•2 months ago
|
Description
•