← TurkTrust cases
Bugzilla #1367842 Ca Certificate Compliance Incident

TurkTrust: Non-audited, non-technically-constrained intermediate certs

RESOLVED FIXED TurkTrust
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The case concerns three TurkTrust intermediate certificates that were described as not audited and not technically constrained (including missing EKU and domain constraints) even though they chain up to a Mozilla root store root. The reporter listed the specific intermediate certificates and provided crt.sh links for each. The reporter discussed options such as including the intermediates in audits, revoking them, providing an annual audit statement, or adding them to OneCRL. The reporter later stated that Bug 1381863 had been filed per the CA’s request to add these three non-audited intermediate certificates to OneCRL even though they were not revoked. Mozilla subsequently noted that the intermediates had been added to OneCRL and that they chain to a root certificate with only the Websites trust bit enabled, so no further action was required by Mozilla for this issue. The bug was marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 14:15 UTC Revised: 2026-06-16 18:12 UTC Confidence: 0.84 5 comments
Chronology
  1. A report was filed about three TurkTrust intermediate certificates that were not audited and not technically constrained despite chaining to a Mozilla root.
  2. The intermediates were requested to be added to OneCRL via a related bug (1381863).
  3. Mozilla confirmed the intermediates were added to OneCRL and that no further Mozilla action was required for this issue.
Thread Activity
  1. Community commenter — Reported three TurkTrust intermediate certificates that were not audited and not technically constrained (no EKU/domain constraints) and listed crt.sh links and possible remediation options.
  2. Community commenter — Corrected the earlier discussion about adding certificates to OneCRL, stating it would be OK for two intermediates not intended for TLS/SSL issuance.
  3. Community commenter — Stated Bug 1381863 was filed per the CA’s request to add the three non-audited intermediate certificates to OneCRL even though they are not revoked.
  4. Community commenter — Noted that Bug 13811863 was resolved as remediation and that it was unclear what additional process/issuance-flow information Mozilla wanted.
  5. Community commenter — Confirmed the intermediates were added to OneCRL and that, because they chain to a root with only the Websites trust bit enabled, no further Mozilla action was required for this issue.
Participants
Community commenter Turktrust representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1398246 RESOLVED Ca Certificate Compliance Incident Opened 2017-09-08 · Closed 2023-02-22 · 70% similar
Consorci AOC: Non-BR-Compliant OCSP Responders
#2056223 ASSIGNED Ca Certificate Compliance Incident Externally Reported Incident Policy Document Issue Opened 2026-07-20 Still Open · 69% similar
D-Trust OCSP Responder Certificates Include CA/B Forum DV Policy OID
#1620727 RESOLVED Ca Certificate Compliance Incident Opened 2020-03-07 · Closed 2023-02-22 · 69% similar
Microsoft DSRE PKI: OCSP responders found to respond signed by the default CA when passed an invalid issuer in request
#1918427 RESOLVED Ca Certificate Compliance Incident Closure Request Opened 2024-09-12 · Closed 2024-10-11 · 69% similar
D-Trust: Non-compliance of issued root and intermediate S/MIME certificates
#2053131 ASSIGNED Ca Certificate Compliance Incident Externally Reported Incident Problem Reporting Failure Opened 2026-07-07 Still Open · 67% similar
TunTrust: OCSP responder "Unknown" of one Pre-certificate
#2049237 ASSIGNED Ca Certificate Compliance Incident Externally Reported Incident Revocation Issue Opened 2026-06-22 Still Open · 67% similar
HARICA: Continued issuance and refusal to revoke TLS certificates for EU-sanctioned blocked entities (Sberbank, VTB, KAMAZ, ANO Dialog)
#1391054 RESOLVED Ca Certificate Compliance Incident Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 64% similar
Izenpe: Non-BR-Compliant Certificate Issuance
#1398255 RESOLVED Ca Certificate Compliance Incident Opened 2017-09-08 · Closed 2023-02-22 · 64% similar
IdenTrust: Non-BR-Compliant OCSP Responders

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action