← D-TRUST cases
Bugzilla #1647468
Ca Certificate Compliance
D-TRUST: Wrong key usage (Key Encipherment)
RESOLVED
FIXED
D-TRUST
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
D-TRUST discovered a compliance issue where a certificate was incorrectly issued with 'keyEncipherment' instead of 'keyAgreement'. The CA identified the problem through internal quality checks shortly after issuance on June 22, 2020. The certificate was revoked within hours of issuance, and D-TRUST halted further certificate production from the affected CA until the issue was resolved. A thorough analysis was conducted, and corrective measures were implemented to prevent recurrence. The CA has since resumed operations after addressing the misconfiguration.
Chronology
- D-TRUST issued a certificate with incorrect key usage.
- The certificate was revoked within hours of issuance.
- D-TRUST resumed certificate production after resolving the issue.
Thread Activity
- Bdr representative — D-TRUST reported a certificate issued with wrong key usage.
- Bdr representative — Final incident report submitted detailing the corrective actions taken.
- Mozilla representative — Indicated intent to close the case unless further issues arise.
Participants
Bdr representative
Community commenter
Mozilla representative
External References
Similar Local Cases
D-TRUST: Issuance of non-conformant SSL certificate
D-Trust: Issuance of an EV certificate containing a mixup of the Subject's postalCode and localityName
D-TRUST: Certificate with RSA key where modulus is not divisible by 8
D-Trust: Missed Revocation of TLS certificates affected by Bugzilla 1884714
D-TRUST: Private Key Disclosed by Customer as Part of CSR
D-Trust: QCStatement with http link of PKI Disclosure Statements
D-Trust: CRL HTTP Media Type
DigiCert: Issuance of Cert with Compromised Key