Izenpe: EV certificate profile issues (missing localityName, disallowed SAN entries, policy extension string type)
The bug reports that an Izenpe EV certificate had multiple issues relative to Mozilla/CA/B Forum Baseline Requirements for EV certificates. Kurt Roeckx listed problems including the absence of localityName, SAN entries containing email and DirName that are not allowed by the BR requirements, and a policy extension user notice explicitText using VisibleString where UTF8String is required (or IA5String may be used). Izenpe acknowledged the issues and attributed them to a specific Spanish “sede electrónica” certificate mandated by law, stating they were working with the ministry and planned changes tied to eIDAS. Izenpe later stated they updated their EV certificate profile to include localityName, remove DirName from SAN, and use UTF8String for the policy extension user notice, but said production issuance would wait until the Spanish Ministry verified the new profile. The bug was marked RESOLVED with resolution FIXED after Izenpe reported that its officeEV certificate profile had been updated and pointed to a last issued certificate for review.
- A specific Izenpe EV certificate was identified as not meeting EV certificate requirements (missing localityName, disallowed SAN contents, and policy extension string type).
- Izenpe explained the issues as stemming from a Spanish ministry-mandated “sede electrónica” certificate and described plans for a new eIDAS-based certificate profile.
- Izenpe confirmed the SAN-related issue was due to specific OIDs that would be removed in a new version to follow BRs and EV requirements.
- Izenpe reported an updated EV certificate profile (localityName added, DirName removed from SAN, UTF8String used) and stated production issuance would wait for ministry verification.
- Izenpe reported its officeEV certificate profile was updated and provided an example of a last issued certificate.
- Roeckx representative — Reported that an EV certificate had issues: missing localityName, SAN containing email and DirName, and policy extension explicitText using VisibleString instead of UTF8String/IA5String.
- Mozilla representative — Asked Iñigo to respond in the bug to the issues listed above.
- Izenpe representative — Acknowledged the issues and said they were due to a Spanish ministry-mandated “sede electrónica” certificate, with plans to define a new eIDAS-based certificate profile.
- Roeckx representative — Asked for clarification on the requirements and how they conflict with the BRs, noting the question about SANs.
- Izenpe representative — Confirmed the issue was with SANs due to specific OIDs that would be removed in the new version.
- Izenpe S.A. — Reported profile updates: include localityName, remove DirName from SAN, and use UTF8String for the policy extension user notice; stated issuance would wait for ministry verification.
- Izenpe S.A. — Reported the officeEV certificate profile was updated and provided a link to a last issued certificate for review.