← Microsec Ltd. cases
Bugzilla #1391055
Ca Certificate Compliance
Incident
Microsec: Non-BR-Compliant Certificate Issuance
RESOLVED
FIXED
Microsec Ltd.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
Microsec Ltd. disclosed multiple non-compliant certificate issuance incidents, including invalid dnsNames and improper key usage settings. The CA became aware of these issues through reports from external auditors and the Mozilla community. In response, Microsec confirmed the revocation of the problematic certificates and outlined steps to prevent future occurrences, including the implementation of automated checks. The CA committed to replacing all non-compliant certificates by the end of November 2017. The case has been resolved with all misissued certificates revoked.
Chronology
- Microsec received a Problem Report regarding invalid dnsNames.
- Microsec revoked a certificate with improper key usage.
- Microsec confirmed the revocation of all misissued certificates.
Thread Activity
- Mozilla representative — Microsec was informed of compliance failures and required to respond.
- Microsec representative — Microsec began addressing the reported problems and outlined their remediation steps.
- Mozilla representative — Gerv noted that the use of unallowed key usage is a violation of standards.
- Mozilla representative — Gerv confirmed acceptance of Microsec's plan to replace non-compliant certificates.
- Microsec representative — Microsec reported the successful revocation of all misissued certificates.
Participants
Mozilla representative
Microsec representative
Community commenter
External References
Similar Local Cases
Disig: Non-BR-Compliant Certificate Issuance
SwissSign: Non-BR-Compliant Certificate Issuance
Firmaprofesional: Non-audited, non-technically-constrained intermediate certificates
GlobalSign: Non-BR-Compliant Certificate Issuance - metadata-only subject fields
Firmaprofesional: Non-BR-Compliant OCSP Responders
DocuSign/Keynectis: Non-BR-Compliant Certificate Issuance
NetLock: Non-BR-Compliant Certificate Issuance
MICROSEC: Incident report - No OCSP status response for 2 Precertificates