TrustAsia Revoked 143 Certificates Following LiteSSL ACME Service Vulnerability
TrustAsia has revoked 143 SSL/TLS certificates due to a vulnerability identified in its LiteSSL ACME service. The issue involved the improper reuse of domain validation data across different ACME accounts, leading to the suspension of issuance services…
TrustAsia has revoked 143 SSL/TLS certificates due to a vulnerability identified in its LiteSSL ACME service. The issue involved the improper reuse of domain validation data across different ACME accounts, leading to the suspension of issuance services and a subsequent revocation of affected certificates.
This incident, documented under Mozilla Bugzilla ticket #2011713, was initiated by a community report on January 21, 2026. The vulnerability affected certificates issued via the ACME protocol after December 29, 2025.
The primary issue arose from a logic error in the LiteSSL ACME service's handling of Authorization objects. It was discovered that authorization data was reused across different ACME accounts, circumventing the need for unique validation per account context.
Total Certificates Impacted: 143 Affected Protocol: ACME (Automated Certificate Management Environment) Vulnerable Period: Issuance dates post-2025-12-29 Status: All affected certificates have been revoked; the service is patched and operational.
The following timeline outlines TrustAsia's response actions on January 21, 2026 (Times in UTC+8).
Time Event Description
14:55 Compliance team received a report regarding domain validation reuse.
15:10 Preliminary confirmation of the issue; ACME issuance service suspended.
TrustAsia has revoked 143 SSL/TLS certificates due to a vulnerability identified in its LiteSSL ACME service.
15:30 Impact scope confirmed; investigation into specific certificates began.
15:33 Revocation initiated for the two specific certificates mentioned in the initial report.
21:00 Code fix completed and validated in the test environment.
21:21 Identification of all 143 affected certificates completed; batch revocation initiated.
21:30 Revocation completed for the 140 remaining valid certificates (3 were previously revoked).
21:41 Patched code deployed to the production environment.
22:35 Reset of all ACME Authorizations from VALID to REVOKED , forcing client re-validation.
23:00 External ACME issuance service fully restored.
This incident violates the CA/Browser Forum Baseline Requirements (TLS BR Version 2.2.2), specifically Section 3.2.2.4, which mandates that the Certificate Authority must validate each Fully-Qualified Domain Name (FQDN) prior to issuance.
TrustAsia has announced that a Full Incident Report will be released to the Mozilla Bugzilla thread, which will include a comprehensive root cause analysis and the definitive start date of the non-compliance.
All ACME Authorizations in the production environment were reset to REVOKED status to prevent any lingering invalid authorizations from being used for new issuance.
Based on reporting by Cyber Security News.
