← Izenpe S.A. cases
Bugzilla #1559765
Certificate Misissuance
Izenpe: Multiple invalid EV certificates issued
RESOLVED
FIXED
Izenpe S.A.
AI Summary
Izenpe S.A. issued multiple invalid Extended Validation (EV) certificates that violated the EV Guidelines. The issues stemmed from incorrect profile definitions and the inclusion of the 'OrganizationIdentifier' attribute in certificates after it was prohibited by the CA/Browser Forum's Ballot SC16. Upon notification of the problem, Izenpe halted the issuance of EV certificates and initiated a review process to identify and revoke the affected certificates. They have since revoked all but one of the misissued certificates and are implementing measures to prevent future occurrences.
Chronology
- Notification received via Bugzilla regarding invalid EV certificates.
- Izenpe stopped issuing EV certificates and began identifying affected certificates.
- Izenpe completed the revocation of all misissued certificates.
Participants
Ryan Sleevi
Oscar Garcia
External References
Similar Local Cases
Izenpe: Non-BR-Compliant OCSP Responders
Izenpe: OU > 64 characters
NetLock: Non-BR-Compliant Certificate Issuance
SwissSign: Misissuance of Intermediate Certificates because of incorrect organizationIdentifier
DigiCert: "Some-State" in stateOrProvinceName
NetLock: CN not in SAN
Kamu SM: "Some-State" in stateOrProvinceName
GRCA: Misissued certificates: Invalid commonName, commonName not in SAN