DocuSign France - Internal names certificates under a technically-constrained subordinate CA
In June 2016, after an audit of a subordinate CA using a technically-constrained certificate, Mozilla identified CP non-compliance and requested the CA to revoke up to 20 internal-name certificates by 1 October 2016. When Mozilla checked again in November 2016, it found that the offending certificates had not been revoked as required, with some recently expired and others still valid, and it also found a newly generated certificate that represented another BR non-compliance. The CA then revoked the affected certificates and made required technical changes, including adding a missing EKU extension in a certificate template. Mozilla reported that two of the three problematic certificates were revoked on 1 December 2016 and the third was revoked on 30 November 2016, and that replacement certificates were generated and submitted to Google CT logs. The thread includes crt.sh links showing the revoked old certificates and the newly created certificates. Kathleen Wilson stated on 13 December 2016 that the bug had been resolved, and the bug is marked RESOLVED with resolution FIXED.
- After an audit of a technically-constrained subordinate CA, CP non-compliance was identified and the CA was asked to revoke internal-name certificates by 2016-10-01.
- The CA had not revoked the offending internal-name certificates as required, and a new non-compliant certificate was generated.
- The CA revoked the remaining problematic certificate.
- The CA revoked two of the problematic certificates and completed required technical changes (including EKU).
- Replacement certificates were generated and pushed to Google CT logs for acceptance.
- Mozilla provided crt.sh links showing revocation status for the old and new certificates.
- The CA owner confirmed the issue was resolved.
- Docusign representative — Mozilla reported that after a June 2016 audit request, the CA had not revoked the offending internal-name certificates by 2016-10-01 and that additional BR non-compliance was found in November 2016.
- Docusign representative — The CA stated that the certificates were revoked (two on 2016-12-01 and one on 2016-11-30), technical changes were made (missing EKU in a template), and replacement certificates were generated and submitted to CT logs.
- Docusign representative — The CA provided crt.sh links showing the old internal-name certificates as revoked and the newly created replacement certificates.
- Mozilla representative — Kathleen Wilson confirmed the bug had been resolved.