← Izenpe S.A. cases
Bugzilla #1391054
Policy Compliance
Izenpe: Non-BR-Compliant Certificate Issuance
RESOLVED
FIXED
Izenpe S.A.
AI Summary
Izenpe S.A. faced issues related to the issuance of non-compliant TLS/SSL certificates, including certificates with invalid DNS names and missing common names in Subject Alternative Names (SANs). The CA was required to provide detailed remediation plans and updates on their progress to ensure compliance with Mozilla's policies. Izenpe has since revoked several problematic certificates and implemented measures to prevent future occurrences, including automatic CSR validation and enhanced auditing processes.
Chronology
- Initial report of non-compliance issues.
- Izenpe implemented CSR validation in production.
- Izenpe updated PKI software for automatic CSR verification.
Participants
Kathleen Wilson
Oscar Garcia
Vincent Lynch
Ryan Sleevi
Jonathan Rudenberg
Gervase Markham
External References
Similar Local Cases
SwissSign: Non-BR-Compliant Certificate Issuance
certSIGN: Non-BR-Compliant Certificate Issuance
Actalis: Non-BR-Compliant Certificate Issuance
Entrust: Non-BR-Compliant Certificate Issuance
Kamu SM: Non-BR-Compliant Certificate Issuance
GoDaddy: Non-BR-Compliant Certificate Issuance
EDICOM: Signing SHA-1 OCSP responses with unconstrained certificate
QuoVadis: Non-BR-Compliant Certificate Issuance