DocuSign/Keynectis: Non-Compliant Technically Constrained Intermediates
This case involves DocuSign (Keynectis) disclosing that two subordinate CAs, 'Orange LB Auth CA Class 2' and 'Orange LB Auth CA G1', were not properly disclosed as technically constrained due to missing DirectoryName constraints. The issue was identified by Mozilla and reported by Wayne Thayer. The CA acknowledged the compliance failure and provided an incident report detailing the timeline of events and the actions taken to address the issue, including plans to disable the serverAuth flag on certain root CAs and revoke the non-compliant issuing CA. The case has been resolved with the CA committing to undergo an audit.
- DocuSign was informed of the compliance issue regarding the subordinate CAs.
- The bug was opened to address the non-compliance.
- The issue was resolved with the CA now listed for audit.
- Fastly representative — Reported that two Keynectis subordinate CAs were not properly disclosed and violated RFC 5280.
- Docusign representative — Provided an incident report detailing the compliance issue and proposed actions.
- Fastly representative — Confirmed that the Orange LB Auth Class 2 CA is now listed for audit.