← Izenpe S.A. cases
Bugzilla #1391054 Ca Certificate Compliance Incident Certificate Misissuance

Izenpe: Non-BR-Compliant Certificate Issuance

RESOLVED FIXED Izenpe S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Izenpe S.A. disclosed a series of non-compliant certificate issuances that violated the CA/Browser Forum Baseline Requirements. The issues included certificates with invalid DNS names, missing Common Names in Subject Alternative Names (SANs), and certificates with serial numbers containing less than 64 bits of entropy. Izenpe acknowledged these problems after they were reported in the Mozilla Dev Security Policy forum and confirmed that they ceased issuing the problematic certificates. They provided a detailed remediation plan, including revocation of affected certificates and implementation of automated checks to prevent future occurrences. The case is now resolved, with Izenpe having completed the necessary actions to address the compliance failures.

Model: gpt-4o-mini Generated: 2026-06-13 17:05 UTC Revised: 2026-06-16 19:09 UTC Confidence: 0.90 22 comments
Chronology
  1. Izenpe became aware of the Common Name not being included in SANs.
  2. Izenpe was notified of certificates with serial numbers less than 64 bits of entropy.
  3. Izenpe was informed of invalid DNS names in certificates.
  4. Izenpe confirmed all pending certificates with issues were revoked.
Thread Activity
  1. Mozilla representative — Izenpe was informed of compliance issues with their certificates.
  2. Community commenter — Izenpe confirmed mis-issuance of certificates without Common Names in SANs.
  3. Izenpe S.A. — Izenpe provided a response detailing their awareness of the issues.
  4. Mozilla representative — Concerns were raised about the delay in addressing the compliance issues.
  5. Izenpe S.A. — Izenpe confirmed updates to their PKI software for CSR verification.
Participants
Community commenter
External References
Similar Local Cases
#1559765 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-06-17 · Closed 2023-02-22 · 91% similar
Izenpe: Multiple invalid EV certificates issued
#1651026 RESOLVED Certificate Misissuance Incident Remediation Tracking Opened 2020-07-07 · Closed 2023-02-22 · 91% similar
Izenpe: certificate issued to internal domain
#1398258 RESOLVED Ca Certificate Compliance Incident Opened 2017-09-08 · Closed 2023-02-22 · 90% similar
Izenpe: Non-BR-Compliant OCSP Responders
#1921254 RESOLVED Certificate Misissuance Self Reported Incident Opened 2024-09-26 · Closed 2025-02-19 · 82% similar
Izenpe: Duplicate attribute in Subject
#1945867 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-02-04 · Closed 2025-04-18 · 82% similar
Izenpe: Incorrect Unicode characters in Subject
#1876565 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-01-25 · Closed 2024-04-06 · 80% similar
Izenpe: Not allowed Qualifier ID OID on Certificate Policies extension
#1996857 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-10-28 · Closed 2025-12-11 · 80% similar
IZENPE: not allowed Key Usage in ocsp responder certificate
#586414 RESOLVED Ca Certificate Compliance Incident Opened 2010-08-11 · Closed 2022-11-14 · 79% similar
Verify GlobalSign's continued conformance to EV guidelines

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action