← Disig, a.s. cases
Bugzilla #1390991
Ca Certificate Compliance
Incident
Certificate Misissuance
Disig: Non-BR-Compliant Certificate Issuance
RESOLVED
FIXED
Disig, a.s.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
Disig, a.s. disclosed a non-compliance issue regarding the issuance of a TLS/SSL certificate that contained invalid dnsNames. The CA became aware of the issue through a Bugzilla notification and confirmed that only one certificate was affected. Disig has since ceased issuing non-compliant certificates and revoked the problematic certificate. They have implemented a blacklist to prevent future occurrences and are enhancing their internal controls to ensure compliance with the Baseline Requirements. The case has been resolved with all actions completed.
Chronology
- Disig informed of non-compliance issue via Bugzilla notification.
- Disig revoked the non-compliant certificate.
- Disig deployed a blacklist to prevent issuance of non-compliant certificates.
- Disig implemented post-issuance controls.
Thread Activity
- Mozilla representative — Disig must respond to compliance issues found in their certificates.
- Disig, a.s. — Disig confirmed they stopped issuing non-compliant certificates.
- Disig, a.s. — Disig reported on the implementation of a blacklist for TLDs.
- Disig, a.s. — Disig provided an update on progress regarding compliance measures.
- Fastly representative — The case was marked as resolved after all actions were completed.
Participants
Mozilla representative
Disig, a.s.
Community commenter
Fastly representative
External References
Similar Local Cases
Microsec: Non-BR-Compliant Certificate Issuance
Disig: Non-BR-Compliant OCSP Responders
Firmaprofesional: Non-BR-Compliant OCSP Responders
Disig: Certificates with invalid embedded SCT signature
NetLock: Non-BR-Compliant Certificate Issuance
GlobalSign: Non-BR-Compliant Certificate Issuance - metadata-only subject fields
Firmaprofesional: Non-audited, non-technically-constrained intermediate certificates
Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record