← DocuSign (OpenTrust/Keynectis) cases
Bugzilla #1321354 Revocation Issue Incident

DocuSign France - Internal names certificates under a technically-constrained subordinate CA

RESOLVED FIXED DocuSign (OpenTrust/Keynectis)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

In June 2016, after an audit of a subordinate CA using a technically-constrained certificate, Mozilla identified CP non-compliance and requested the CA to revoke up to 20 internal-name certificates by 1 October 2016. When Mozilla checked again in November 2016, it found that the offending certificates had not been revoked as required, with some recently expired and others still valid, and it also found a newly generated certificate that represented another BR non-compliance. The CA then revoked the affected certificates and made required technical changes, including adding a missing EKU extension in a certificate template. Mozilla reported that two of the three problematic certificates were revoked on 1 December 2016 and the third was revoked on 30 November 2016, and that replacement certificates were generated and submitted to Google CT logs. The thread includes crt.sh links showing the revoked old certificates and the newly created certificates. Kathleen Wilson stated on 13 December 2016 that the bug had been resolved, and the bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 14:09 UTC Revised: 2026-06-16 18:33 UTC Confidence: 0.86 4 comments
Chronology
  1. After an audit of a technically-constrained subordinate CA, CP non-compliance was identified and the CA was asked to revoke internal-name certificates by 2016-10-01.
  2. The CA had not revoked the offending internal-name certificates as required, and a new non-compliant certificate was generated.
  3. The CA revoked the remaining problematic certificate.
  4. The CA revoked two of the problematic certificates and completed required technical changes (including EKU).
  5. Replacement certificates were generated and pushed to Google CT logs for acceptance.
  6. Mozilla provided crt.sh links showing revocation status for the old and new certificates.
  7. The CA owner confirmed the issue was resolved.
Thread Activity
  1. Docusign representative — Mozilla reported that after a June 2016 audit request, the CA had not revoked the offending internal-name certificates by 2016-10-01 and that additional BR non-compliance was found in November 2016.
  2. Docusign representative — The CA stated that the certificates were revoked (two on 2016-12-01 and one on 2016-11-30), technical changes were made (missing EKU in a template), and replacement certificates were generated and submitted to CT logs.
  3. Docusign representative — The CA provided crt.sh links showing the old internal-name certificates as revoked and the newly created replacement certificates.
  4. Mozilla representative — Kathleen Wilson confirmed the bug had been resolved.
Participants
Docusign representative Mozilla representative
Similar Local Cases
#1391000 RESOLVED Ca Certificate Compliance Incident Revocation Issue Opened 2017-08-16 · Closed 2023-02-22 · 71% similar
IdenTrust: Non-BR-Compliant Certificate Issuance
#1523680 RESOLVED Revocation Issue Incident Opened 2019-01-29 · Closed 2023-02-22 · 70% similar
Actalis: Non BR Compliant OCSP Responder
#1397830 RESOLVED Certificate Misissuance Revocation Issue Opened 2017-09-07 · Closed 2023-02-22 · 67% similar
EDICOM: Signing SHA-1 OCSP responses with unconstrained certificate
#1596744 RESOLVED Delayed Revocation Incident Opened 2019-11-15 · Closed 2024-06-30 · 61% similar
Izenpe: Intermediate CA certificates not listed in audit report
#1536831 RESOLVED Ca Certificate Compliance Revocation Issue Remediation Tracking Opened 2019-03-20 · Closed 2023-02-22 · 61% similar
GDCA: Insufficient Serial Number Entropy
#1931886 RESOLVED Revocation Issue Opened 2024-11-18 · Closed 2025-02-12 · 60% similar
Entrust: CRL missing revocation reasonCode
#1483639 RESOLVED Revocation Issue Delayed Revocation Opened 2018-08-15 · Closed 2024-06-30 · 60% similar
DigiCert / ADACOM: published expired CRLs
#1639805 RESOLVED Revocation Issue Delayed Revocation Opened 2020-05-21 · Closed 2023-02-22 · 60% similar
Sectigo: Failure to revoke key-compromised certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action