← DocuSign (OpenTrust/Keynectis) cases
Bugzilla #1444455
Technical Compliance
DocuSign/Keynectis: Non-Compliant Technically Constrained Intermediates
RESOLVED
FIXED
DocuSign (OpenTrust/Keynectis)
AI Summary
The case involves two Keynectis subordinate CAs that were not properly disclosed and contain non-critical name constraints extensions, violating RFC 5280. The issue was raised by Wayne Thayer, who requested an incident report due to the lack of DirectoryName constraints required for technically constrained CAs. The CA owner, DocuSign, acknowledged the problem and proposed actions to disable the serverAuth flag on their root CAs and revoke the existing issuing CA. The case has been resolved with the CA now listed for audit.
Chronology
- Bug opened regarding non-compliance of Keynectis subordinate CAs.
- Incident report provided by DocuSign regarding the non-compliant CAs.
- DocuSign confirmed plans for an audit of the CA.
- Resolution confirmed as the CA is now listed for audit.
Participants
Wayne Thayer
Erwann Abalea
External References
Similar Local Cases
Consorci AOC: Non-BR-Compliant OCSP Responders
Entrust: Non-BR-Compliant OCSP Responder
DigiCert: SCEE / Justica: Non-BR-Compliant Certificate Issuance
Firmaprofesional: Non-BR-Compliant OCSP Responders
Visa: Non-BR-Compliant OCSP Responders
startcom: still issuing < 2048 bit certificates
Amazon Trust Services: CRL not DER-encoded
SwissSign: recommendation on backup testing