← Certigna cases
Bugzilla #1485413
Certificate Misissuance
Certigna: Issuance without respecting CAA records
RESOLVED
FIXED
Certigna
AI Summary
Certigna was found to have issued certificates without adhering to CAA records as required by BR section 3.2.2.8. The CA's current CPS allowed issuance based on a signed authorization from a legal representative, even if the CAA record was not updated. Certigna confirmed this misinterpretation and has been asked to identify and remediate all misissued certificates. An incident report is required to document the issue and its resolution.
Chronology
- Initial report of misissuance due to CAA record non-compliance.
- Follow-up on questions regarding the incident report.
Participants
Wayne Thayer
Josselin Allemandou
External References
Similar Local Cases
Certigna: TLS certificates with Basic constraint non-critical
Certigna: certificates issued with 2 SCT
Dhimyotis / Certigna: Certificates issued with validity periods greater than 398-days
Dhimyotis / Certigna: Certificates issued with validity periods greater than 398-days
Camerfirma: Missing audit for Intermediate certificate
SECOM: CrossTrust: OU > 64 characters
GRCA: Misissued certificates - invalid CN, bad validity period, missing extensions
Microsec: Validity period greater than 825 days