← DarkMatter LLC cases
Bugzilla #1468477
Certificate Problem Report
QuoVadis / Freistaat Bayern: Non-BR-compliant Key Usage
RESOLVED
FIXED
DarkMatter LLC
AI Summary
A certificate issued by Freistaat Bayern under a QuoVadis root was found to have non-compliant Key Usage extensions, specifically allowing keyCertSign and cRLSign for an end-entity certificate. The issue was identified on June 12, 2018, through a post-issuance linting system, leading to the certificate's revocation on June 13, 2018. QuoVadis has since implemented tighter controls and is transitioning to a managed PKI to prevent future occurrences. The problematic certificates were revoked by December 30, 2019.
Chronology
- Issue identified via post-issuance linting system.
- Certificate revoked.
- Freistaat Bayern ceased issuance from the problematic subCA.
- SubCA revoked.
Participants
Rob Stradling
Stephen Davidson
External References
Similar Local Cases
QuoVadis: BR Error - san dns name starts with period
QuoVadis: hostnames not in preferred name syntax
QuoVadis: N/A in EV serialNumber field
QuoVadis / Siemens: Insufficient serial number entropy
QuoVadis: Incorrect EV businessCategory
QuoVadis: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy or the BRs
QuoVadis: Unconstrained CAs revocation
QuoVadis: IP in dnsName