← DigiCert cases
Bugzilla #1518555 Certificate Misissuance

DigiCert: Use of forbidden subjectPublicKeyInfo algorithm (P-521)

RESOLVED FIXED DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns certificates issued by DigiCert that used the forbidden subjectPublicKeyInfo algorithm P-521. The issue was reported in the mozilla.dev.security.policy forum and the bug asked DigiCert to provide an incident report. DigiCert identified three certificates issued after the effective date of Mozilla policy 2.4 that used P-521, and Jeremy Rowley stated they were looking into why they were issued after Feb 28, 2017. DigiCert said it blocked all issuance of the certificates in August 2017 and patched the CA to prevent P-521 certificates for any publicly trusted certificates. DigiCert also discussed revocation timing, stating that the certificates were technically compliant with CAB Forum requirements but not with Mozilla policy, and that they were working on internal reviews and governance changes to better capture past and future policy changes. The bug was marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 11:25 UTC Revised: 2026-06-16 18:57 UTC Confidence: 0.86 10 comments
Chronology
  1. DigiCert issued a publicly trusted server CA certificate using P-521 after Mozilla policy 2.4 was released.
  2. DigiCert issued another publicly trusted server CA certificate using P-521 after Mozilla policy 2.4 was released.
  3. DigiCert issued a third publicly trusted server CA certificate using P-521 after Mozilla policy 2.4 was released.
  4. DigiCert blocked issuance of the affected certificates.
  5. Mozilla requested DigiCert provide an incident report after certificates using P-521 were reported in mozilla.dev.security.policy.
  6. DigiCert provided a timeline and remediation steps, including process changes and the CA patch to prevent P-521 issuance.
Thread Activity
  1. Community commenter — Reported that problems were found in certificates issued by DigiCert and asked DigiCert to provide an incident report, citing P-521 certificates discussed in mozilla.dev.security.policy.
  2. Community commenter — Requested that Jeremy provide an incident report on behalf of DigiCert.
  3. DigiCert — Listed three certificates issued after policy 2.4’s effective date that used P-521 and said they were looking into why they were issued after Feb 28, 2017.
  4. DigiCert — Provided steps to reproduce and a response timeline, stating they blocked all issuance in August 2017 and describing compliance governance changes.
  5. DigiCert — Stated the fix was to patch the CA to prevent P-521 certificates for any publicly trusted certificates.
  6. Community commenter — Asked what processes or controls changed to ensure timely retroactive review and revocation, referencing the comment about not reporting/revoking the certificate issued after Jun 23.
  7. DigiCert — Explained the revocation debate, stating the certificates were CAB Forum compliant but not Mozilla policy compliant, and described future and past compliance review efforts.
  8. Community commenter — Flagged a question for Wayne on whether Mozilla policy violations should be treated as BR violations and noted ambiguity created by BR revocation changes.
  9. Fastly representative — Provided an interpretation that Mozilla policy does not set revocation requirements for these certificates and suggested policy clarification.
  10. Community commenter — Agreed the remediation steps described in the thread could resolve the issue and referenced a linked message in mozilla.dev.security.policy.
Participants
Community commenter DigiCert Fastly representative
Similar Local Cases
#1398269 RESOLVED Certificate Misissuance Opened 2017-09-08 · Closed 2023-02-22 · 100% similar
DigiCert: Non-BR-Compliant OCSP Responders
#1675923 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-11-07 · Closed 2024-05-09 · 88% similar
DigiCert: TERENA: Insufficient validation of organizationalUnitName
#1710856 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-05-12 · Closed 2023-02-22 · 88% similar
DigiCert: Invalid localityName
#1586604 RESOLVED Certificate Misissuance Validation Issue Opened 2019-10-06 · Closed 2022-11-14 · 87% similar
DigiCert: TERENA: No localityName in EV precert
#1531817 RESOLVED Certificate Misissuance Opened 2019-03-01 · Closed 2023-02-22 · 86% similar
DigiCert: in-addr.arpa Misissuance
#1550645 RESOLVED Certificate Misissuance Opened 2019-05-10 · Closed 2023-02-22 · 84% similar
DigiCert: CAA Checking Issue
#1527423 RESOLVED Certificate Misissuance Opened 2019-02-12 · Closed 2023-02-22 · 80% similar
DigiCert: P-384,ecdsa-with-SHA512 Certificates
#1759122 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-03-11 · Closed 2022-11-14 · 79% similar
DigiCert: EV for Onion addresses without Tor Service Descriptor

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action