Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

IdenTrust mis-issuance of an EV SSL Certificate

323 views
Skip to first unread message

IdenTrust Inc

unread,
Apr 28, 2020, 6:14:27 PM4/28/20
to mozilla-dev-s...@lists.mozilla.org
Today 4/28/2020 we issued an internal end-entity EV SSL certificate that was immediately caught and revoked prior to deployment as we noted certain details in the Subject that were not accurate.
A formal incident report will follow while we investigate, document the details, and undertake corrective actions.
This the certificate: https://crt.sh/?id=2740887794

IdenTrust Inc

unread,
May 1, 2020, 4:50:18 PM5/1/20
to mozilla-dev-s...@lists.mozilla.org
This issue has been corrected and a temporary solution to avoid recurrence was implemented on the same day it was encountered; we are still in the process of formulating permanent corrective measures and solution to share with the community via the expected formal Incident Report.

Ryan Sleevi

unread,
May 4, 2020, 6:05:53 PM5/4/20
to IdenTrust Inc, mozilla-dev-security-policy
Thanks. I filed https://bugzilla.mozilla.org/show_bug.cgi?id=1635279
so you can fill in with the fuller set of details requested from
https://wiki.mozilla.org/CA/Responding_To_An_Incident

On Fri, May 1, 2020 at 4:50 PM IdenTrust Inc via dev-security-policy
<dev-secur...@lists.mozilla.org> wrote:
>
> This issue has been corrected and a temporary solution to avoid recurrence was implemented on the same day it was encountered; we are still in the process of formulating permanent corrective measures and solution to share with the community via the expected formal Incident Report.
>
> _______________________________________________
> dev-security-policy mailing list
> dev-secur...@lists.mozilla.org
> https://lists.mozilla.org/listinfo/dev-security-policy
0 new messages