← e-tugra cases
Bugzilla #1449371 Ca Certificate Compliance Certificate Misissuance

E-Tugra: Validity period > 825 days

RESOLVED FIXED e-tugra
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns an E-Tugra certificate that contained multiple Baseline Requirements errors, including a validity period greater than allowed (over 825 days). The issue was reported externally by Wayne Thayer (Fastly) with a reference to the certificate on crt.sh and a request for an incident report. E-Tugra stated it took action to fix the problem, including revoking the related certificate and issuing a new certificate for the certificate owner, and searching its certificate database for additional instances. In its incident report, E-Tugra described that it implemented an 825-day validity limit on February 21, 2018, but that due to payment latency the certificate was issued with approved data that covered a validity date over 825 days; E-Tugra also described additional issues involving missing localityName/stateOrProvinceName and an unallowed key usage (key agreement) for RSA public key. E-Tugra reported that it found no more certificates with the 825-day validity problem, replaced another certificate with the localityName/stateOrProvinceName issue, and set server certificates to address the key-agreement flag issue. The bug was marked resolved after the updated incident report and follow-up discussion, and the resolution is FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 17:46 UTC Revised: 2026-06-16 18:29 UTC Confidence: 0.86 7 comments
Chronology
  1. A certificate was issued with a validity period that exceeded the 825-day limit (as described in the incident report).
  2. A Bugzilla report was filed identifying Baseline Requirements errors in the certificate, including validity period > 825 days.
  3. E-Tugra stated it revoked the certificate and planned to provide an incident report after root analysis.
  4. E-Tugra submitted an updated incident report describing causes and remediation steps for the identified BR violations.
  5. The reporter confirmed the updated incident report and marked the bug resolved.
Thread Activity
  1. Fastly representative — Reported that the certificate had errors including a validity period greater than allowed and requested an incident report, linking to crt.sh.
  2. E-Tugra — Said E-Tugra would fix the problem, that the certificate was being revoked as soon as possible, and that the incident report would follow after root analysis.
  3. E-Tugra — Provided an incident report describing revocation, database search, root cause analysis, system library upgrades/testing, and steps to prevent recurrence.
  4. Fastly representative — Requested reporting on additional BR violations found in the certificate (missing localityName/stateOrProvinceName and unallowed RSA key usage for key agreement).
  5. E-Tugra — Indicated the incident report would be updated ASAP.
  6. E-Tugra — Submitted an updated incident report covering the additional BR violations and remediation, including replacing another affected certificate and removing/fixing the key-agreement flag issue.
  7. Fastly representative — Acknowledged the updated report, discussed the key-agreement flag rationale and fix, and marked the bug resolved.
Participants
Fastly representative E-Tugra
Similar Local Cases
#1462797 RESOLVED Certificate Misissuance Opened 2018-05-18 · Closed 2023-02-22 · 82% similar
E-Tugra: Improper DER results in failure to comply with RFC 5280 - Invalid characters in PrintableString
#1512270 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2018-12-05 · Closed 2023-02-22 · 79% similar
Microsec: Validity period greater than 825 days
#1431164 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2018-01-17 · Closed 2023-02-22 · 78% similar
Camerfirma: Non-BR-Compliant Issuance - Non-printable characters in OU field
#1582601 RESOLVED Self Reported Incident Certificate Misissuance Opened 2019-09-20 · Closed 2023-02-22 · 76% similar
E-Tugra: Invalid DER results in failure to comply with RFC 5280 - Violating string length limit
#1502957 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2018-10-29 · Closed 2023-02-22 · 71% similar
Camerfirma: MULTICERT Misissuance and missing audits
#1267049 RESOLVED Certificate Misissuance Opened 2016-04-24 · Closed 2023-02-22 · 71% similar
Izenpe: EV certificate with various issues
#1048045 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2014-08-03 · Closed 2022-11-14 · 71% similar
GlobalSign Partner: No SAN
#1436173 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2018-02-06 · Closed 2023-02-22 · 71% similar
DigiCert: SCEE / Justica: Non-BR-Compliant Certificate Issuance

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action