← Apple Inc. cases
Bugzilla #1777757
Certificate Misissuance
Apple: EV TLS pre-certificates issued without EKU extension
RESOLVED
FIXED
Apple Inc.
AI Summary
On July 1, 2022, Apple Public CA issued two EV TLS pre-certificates without an Extended Key Usage (EKU) extension, violating Baseline Requirements. The certificates were revoked shortly after issuance, and Apple identified a bug in their deployment process that led to this misconfiguration. A series of corrective actions were taken, including the implementation of a fix from their software vendor. The issue has since been resolved, and the CA continues to monitor for any further questions.
Chronology
- Two EV TLS pre-certificates issued without EKU extension.
- Certificates revoked after identification of the issue.
- Production environment upgraded to include the fix for the bug.
Participants
Apple CA
Mozilla
External References
Similar Local Cases
SHA-1 issuance by DocuSign root
GlobalSign Partner: No SAN
DigiCert: Mis-Issuance Rekey certificates
Camerfirma: Non-BR-Compliant Issuance - DNSName is empty
Let's Encrypt: certs issued contrary to CPS due to incomplete blocklist
DigiCert: SMIME certificates issued inconsistent with BR’s
DigiCert / Inteso San Paulo: Double dot characters
DigiCert / Terena: Metadata in OU fields