← PROCERT cases
Bugzilla #1391058
Certificate Problem Report
PROCERT: Non-BR-Compliant Certificate Issuance
RESOLVED
DUPLICATE
PROCERT
AI Summary
PROCERT has been found to issue certificates that do not comply with the Baseline Requirements (BRs), including invalid Subject Alternative Names (SANs) and improper serial number generation. The issues were reported in the mozilla.dev.security.policy forum, prompting a request for PROCERT to provide a detailed remediation plan. Despite some responses, concerns remain about the CA's compliance and the effectiveness of its corrective actions. The case has been marked as resolved but is noted as a duplicate of another case, indicating ongoing scrutiny of PROCERT's practices.
Chronology
- Initial report of non-compliance issues.
- PROCERT acknowledges issues and begins remediation.
- Annual audit information submitted.
- Further updates on compliance measures provided.
- Case marked as duplicate of another ongoing issue.
Participants
kathleen.a.wilson@gmail.com
alejandrovolcan@gmail.com
ryan.sleevi@gmail.com
gerv@mozilla.org
soporte@procert.net.ve
External References
Similar Local Cases
Camerfirma: Multicert SSL CA 001: Insufficient serial number entropy
Firmaprofesional: AC Firmaprofesional - INFRAESTRUCTURA insufficient serial number entropy
GDCA: Insufficient Serial Number Entropy
DigiCert: Apple: Non-compliant Common Name Length
IPSCA SSL Cert not Accepted in Mozilla, Accepted in IE8
Atos: Insufficient Serial Number Entropy
Camerfirma: Multicert SSL CA 001: Insufficient serial number entropy
Apple: OCSP responders return responses with incorrect issuer