← DocuSign (OpenTrust/Keynectis) cases
Bugzilla #1313873 Ca Certificate Compliance Certificate Misissuance

SHA-1 certificates erroneously issued by DocuSign (OpenTrust/Keynectis) root

RESOLVED FIXED DocuSign (OpenTrust/Keynectis)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Mozilla received reports of SHA-1 certificates chaining up to CAs trusted by Mozilla that had not been brought up on the list or in Bugzilla. The certificates were described as chaining to “Class 2 Primary CA” (DocuSign (OpenTrust/Keynectis)) via “CLASS 2 KEYNECTIS CA,” and the report stated this was a violation of the Baseline Requirements. DocuSign responded that its CP/CPS forbids SHA-1 and mandates SHA-256, and that four SHA-1 certificates were erroneously issued. DocuSign stated that two certificates were revoked on 11 February 2016 and the other two were revoked on 26 May 2016. DocuSign explained that technical and organizational controls at the RA level were not followed for two certificates due to access-rights issues, and that the fault was detected during internal self-audits, after which access rights were corrected and procedures reminded. DocuSign also stated it could not disable SHA-1 workspaces immediately because it would prevent RA actors from revoking certificates associated with those workspaces, and it planned to set up technical means to make SHA-1 issuance always fail by modifying certificate templates at the CA level. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 14:07 UTC Revised: 2026-06-16 18:31 UTC Confidence: 0.90 7 comments
Chronology
  1. Mozilla security policy discussion identified SHA-1 certificates chaining to the DocuSign (OpenTrust/Keynectis) hierarchy that were not previously reported.
  2. DocuSign provided details of four erroneously issued SHA-1 certificates and their revocation dates, and described corrective actions and planned template changes.
Thread Activity
  1. Community commenter — Gerv asked DocuSign to explain the SHA-1 issuance, including CP/CPS restrictions, audit status, and technical controls bypassed.
  2. Community commenter — Kathleen Wilson asked Erwann to investigate and update the bug with the requested information.
  3. Community commenter — Gerv added another crt.sh link for an additional SHA-1 certificate.
  4. Docusign representative — Erwann Abalea stated the CP/CPS forbids SHA-1, provided audit information, described RA-level access-rights control failures for four certificates, and reported revocation dates and corrective actions plus a plan to modify CA-level templates to prevent SHA-1 issuance.
  5. Docusign representative — Erwann corrected a serial-number typo and provided crt.sh links for the certificates.
  6. Community commenter — Gerv thanked DocuSign for the explanation and the steps to prevent recurrence.
Participants
Mozilla representative Docusign representative
Similar Local Cases
#1398427 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-09-09 · Closed 2023-02-22 · 85% similar
Let's Encrypt: CAA Misissuances
#1369359 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-06-01 · Closed 2023-02-22 · 85% similar
StartCom: mis-issuance of certs with unvalidated domain names and bogus field values
#1319609 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2016-11-23 · Closed 2023-02-22 · 84% similar
Let's Encrypt: certs issued contrary to CPS due to incomplete blocklist
#1390994 RESOLVED Ca Certificate Compliance Opened 2017-08-16 · Closed 2023-02-22 · 84% similar
DocuSign/Keynectis: Non-BR-Compliant Certificate Issuance
#1398247 RESOLVED Ca Certificate Compliance Opened 2017-09-08 · Closed 2023-02-22 · 82% similar
DocuSign/Keynectis: Non-BR-Compliant OCSP Responders
#1386894 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-08-03 · Closed 2023-02-22 · 78% similar
StartCom: Non-BR-Compliant Certificate Issuance -- adding Certnomis intermediates to OneCRL
#1401211 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-09-19 · Closed 2023-02-22 · 78% similar
NetLock: Non-BR-Compliant Certificate Issuance -- * in not the leftmost position in dnsName
#1339339 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-02-14 · Closed 2023-02-22 · 78% similar
DigiCert: Non-BR Compliant Certificates - missing CP/CPS OID

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action