Izenpe: Non-BR-Compliant Certificate Issuance
Izenpe S.A. disclosed a series of non-compliant certificate issuances that violated the CA/Browser Forum Baseline Requirements. The issues included certificates with invalid DNS names, missing Common Names in Subject Alternative Names (SANs), and certificates with serial numbers containing less than 64 bits of entropy. Izenpe acknowledged these problems after they were reported in the Mozilla Dev Security Policy forum and confirmed that they ceased issuing the problematic certificates. They provided a detailed remediation plan, including revocation of affected certificates and implementation of automated checks to prevent future occurrences. The case is now resolved, with Izenpe having completed the necessary actions to address the compliance failures.
- Izenpe became aware of the Common Name not being included in SANs.
- Izenpe was notified of certificates with serial numbers less than 64 bits of entropy.
- Izenpe was informed of invalid DNS names in certificates.
- Izenpe confirmed all pending certificates with issues were revoked.
- Mozilla representative — Izenpe was informed of compliance issues with their certificates.
- Community commenter — Izenpe confirmed mis-issuance of certificates without Common Names in SANs.
- Izenpe S.A. — Izenpe provided a response detailing their awareness of the issues.
- Mozilla representative — Concerns were raised about the delay in addressing the compliance issues.
- Izenpe S.A. — Izenpe confirmed updates to their PKI software for CSR verification.