Visa: Non-BR-Compliant Certificate Issuance
Visa faced issues with the issuance of non-Baseline Requirements (BR) compliant certificates, particularly concerning invalid dnsNames and missing serverAuth key purposes. The problems were reported in the Mozilla security policy forum, prompting Visa to confirm that they ceased issuing such certificates and began remediation efforts. They provided a timeline for revocation and replacement of the problematic certificates, with commitments to improve their compliance processes. Visa acknowledged the need for better internal handling of problem reports and has since updated their procedures to ensure timely responses.
- Problems reported in Mozilla security policy forum.
- First problematic certificate revoked.
- Second problematic certificate scheduled for revocation.