← Disig, a.s. cases
Bugzilla #1390991 Ca Certificate Compliance Incident Certificate Misissuance

Disig: Non-BR-Compliant Certificate Issuance

RESOLVED FIXED Disig, a.s.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Disig, a.s. disclosed a non-compliance issue regarding the issuance of a TLS/SSL certificate that contained invalid dnsNames. The CA became aware of the issue through a Bugzilla notification and confirmed that only one certificate was affected. Disig has since ceased issuing non-compliant certificates and revoked the problematic certificate. They have implemented a blacklist to prevent future occurrences and are enhancing their internal controls to ensure compliance with the Baseline Requirements. The case has been resolved with all actions completed.

Model: gpt-4o-mini Generated: 2026-06-13 17:04 UTC Revised: 2026-06-16 18:29 UTC Confidence: 0.90 16 comments
Chronology
  1. Disig informed of non-compliance issue via Bugzilla notification.
  2. Disig revoked the non-compliant certificate.
  3. Disig deployed a blacklist to prevent issuance of non-compliant certificates.
  4. Disig implemented post-issuance controls.
Thread Activity
  1. Mozilla representative — Disig must respond to compliance issues found in their certificates.
  2. Disig, a.s. — Disig confirmed they stopped issuing non-compliant certificates.
  3. Disig, a.s. — Disig reported on the implementation of a blacklist for TLDs.
  4. Disig, a.s. — Disig provided an update on progress regarding compliance measures.
  5. Fastly representative — The case was marked as resolved after all actions were completed.
Participants
Mozilla representative Disig, a.s. Community commenter Fastly representative
External References
Similar Local Cases
#1391055 RESOLVED Ca Certificate Compliance Incident Opened 2017-08-16 · Closed 2023-02-22 · 100% similar
Microsec: Non-BR-Compliant Certificate Issuance
#1398242 RESOLVED Incident Opened 2017-09-08 · Closed 2023-02-22 · 100% similar
Disig: Non-BR-Compliant OCSP Responders
#1398240 RESOLVED Ca Certificate Compliance Incident Opened 2017-09-08 · Closed 2023-02-22 · 98% similar
Firmaprofesional: Non-BR-Compliant OCSP Responders
#2007132 RESOLVED Certificate Misissuance Self Reported Incident Opened 2025-12-19 · Closed 2026-02-11 · 94% similar
Disig: Certificates with invalid embedded SCT signature
#1391056 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-08-16 · Closed 2023-02-22 · 93% similar
NetLock: Non-BR-Compliant Certificate Issuance
#1390997 RESOLVED Ca Certificate Compliance Incident Revocation Issue Opened 2017-08-16 · Closed 2023-02-22 · 93% similar
GlobalSign: Non-BR-Compliant Certificate Issuance - metadata-only subject fields
#1368171 RESOLVED Ca Certificate Compliance Incident Opened 2017-05-26 · Closed 2024-06-30 · 93% similar
Firmaprofesional: Non-audited, non-technically-constrained intermediate certificates
#1409766 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Opened 2017-10-18 · Closed 2023-02-22 · 93% similar
Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action