← Izenpe S.A. cases
Bugzilla #1596744
Certificate Problem Report
Izenpe: Intermediate CA certificates not listed in audit report
RESOLVED
FIXED
Izenpe S.A.
AI Summary
Izenpe S.A. identified that several intermediate CA certificates were not included in their audit report, leading to a compliance issue. The CA became aware of the problem through the CCADB Audit Letter Validation results on November 14, 2019. They took immediate action by revoking all affected certificates, which included both SSL/TLS and non-SSL/TLS certificates. The revocation process was completed by the end of November 2019, and all necessary steps were taken to ensure compliance with the Baseline Requirements.
Chronology
- Logged into CCADB but misinterpreted the information.
- Decided to prepare a plan to revoke all affected certificates.
- Revoked all subCAs issuing SSL/TLS certificates.
- Revoked all pending subCAs.
- Confirmed that all questions were answered and remediation was complete.
Participants
Oscar Garcia
Ryan Sleevi
External References
Similar Local Cases
Izenpe: intermediate certificates not revoked within BR time period
Izenpe: Failure to revoke within 5 days
Izenpe: Failure to provide a preliminary report within 24 hours.
Izenpe: Certificates not disclosed in CCADB
Izenpe: Multiple sub CAs with incorrectly encoded SubjectPublicKeyInfo algorithm
Izenpe: Not allowed Qualifier ID OID on Certificate Policies extension
E-Tugra: Insufficient serial number entropy
Consorci AOC: EC-SECTORPUBLIC insufficient serial number entropy