← D-TRUST cases
Bugzilla #1075952 Ca Certificate Compliance Certificate Misissuance

D-Trust: issuing 1024 bit certificates

RESOLVED WORKSFORME D-TRUST
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The reporter observed a recent 1024-bit RSA certificate in a chain issued by D-TRUST. The certificates identified were issued under the D-TRUST Root Class 3 CA 2 2009 and D-TRUST SSL Class 3 CA 1 2009. D-TRUST staff responded that they had found two certificates with this key length requested by one customer. They stated that the two certificates were revoked immediately and that the customer was informed. D-TRUST also noted that the bug had been included within website application updates and that it would implement further mechanisms and additional test resources to avoid similar accidents in the future. The reporter asked whether the bug should be closed as fixed, and later indicated they did not see a recent occurrence and closed the bug for now. The bug is marked RESOLVED with resolution WORKSFORME.

Model: gpt-5.4-nano Generated: 2026-06-13 13:59 UTC Revised: 2026-06-16 18:27 UTC Confidence: 0.86 4 comments
Chronology
  1. A 1024-bit RSA certificate was observed in a D-TRUST certificate chain.
  2. D-TRUST identified two 1024-bit certificates and revoked them immediately.
  3. The reporter closed the bug for now after not seeing a recent occurrence.
Thread Activity
  1. Roeckx representative — Reported seeing a recent 1024-bit RSA certificate from the D-TRUST chain and provided the subject details.
  2. D-Trust — Confirmed they found two certificates with this key length requested by one customer, said they were revoked immediately, and stated the customer was informed; also said they would add mechanisms and more testing to prevent future accidents.
  3. Mozilla representative — Asked whether the bug should be closed as fixed.
  4. Roeckx representative — Said they didn't see a recent one and closed the bug for now.
Participants
Roeckx representative D-Trust Mozilla representative
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#1390990 RESOLVED Certificate Misissuance Delayed Revocation Opened 2017-08-16 · Closed 2023-02-22 · 95% similar
D-TRUST: Non-BR-Compliant Certificate Issuance
#1034835 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2014-07-05 · Closed 2022-11-14 · 91% similar
Actalis: Issusing 1024 bit certificates
#2023458 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-03-15 · Closed 2026-06-12 · 88% similar
D-Trust: TLS Precertificates Exceeding the Maximum Validity Period Allowed by the TLS Baseline Requirements
#1319609 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2016-11-23 · Closed 2023-02-22 · 78% similar
Let's Encrypt: certs issued contrary to CPS due to incomplete blocklist
#1369359 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-06-01 · Closed 2023-02-22 · 78% similar
StartCom: mis-issuance of certs with unvalidated domain names and bogus field values
#988633 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2014-03-26 · Closed 2023-02-22 · 78% similar
GoDaddy: improperly encoded certificate issued by Go Daddy Secure Certification Authority
#1313873 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2016-10-29 · Closed 2022-11-14 · 78% similar
SHA-1 issuance by DocuSign root
#1339339 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-02-14 · Closed 2023-02-22 · 78% similar
DigiCert: Non-BR Compliant Certificates - missing CP/CPS OID

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action