← D-TRUST cases
Bugzilla #1610303
Ca Certificate Compliance
D-TRUST: Issuance of non-conformant SSL certificate
RESOLVED
FIXED
D-TRUST
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
D-TRUST reported the issuance of a non-conformant SSL certificate on January 20, 2020, which was promptly revoked by the customer. The CA discovered the issue through its internal alerting systems shortly after the certificate was issued. D-TRUST halted production, corrected the configuration error that allowed the issuance, and implemented a thorough analysis to prevent future occurrences. The CA has since completed a redesign of its configuration processes and successfully deployed the necessary changes to its production system by October 1, 2020.
Chronology
- Issuance of a non-conformant SSL certificate by D-TRUST
- Successful deployment of configuration changes to prevent future issues
Thread Activity
- Bdr representative — D-TRUST issued a non-conformant SSL certificate and took immediate action to revoke it.
- Bdr representative — Final report submitted detailing the incident and corrective actions.
- Mozilla representative — Plan to close the bug as all issues have been addressed.
Participants
Bdr representative
Fastly representative
Community commenter
Mozilla representative
External References
Similar Local Cases
D-TRUST: Wrong key usage (Key Encipherment)
D-Trust: Issuance of an EV certificate containing a mixup of the Subject's postalCode and localityName
D-Trust: Missed Revocation of TLS certificates affected by Bugzilla 1884714
D-TRUST: Certificate with RSA key where modulus is not divisible by 8
D-TRUST: Private Key Disclosed by Customer as Part of CSR
D-Trust: QCStatement with http link of PKI Disclosure Statements
D-Trust: CRL HTTP Media Type
DigiCert: Issuance of Cert with Compromised Key