← Izenpe S.A. cases
Bugzilla #1651026 Certificate Misissuance Incident Remediation Tracking

Izenpe incident: certificate issued for an internal domain due to CSR mix-up

RESOLVED FIXED Izenpe S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Izenpe reported that one TLS certificate was misissued because the operator used the CSR for an internal CA request when issuing a certificate for an external domain. The problem was first detected by Izenpe’s internal detection system on 2020-07-06, and the affected certificate was revoked shortly after. Izenpe said the root cause was a mismatch between the CSR and the application form, combined with a manual contingency path that allowed requests outside the web application. Mozilla reviewers asked for more detail about the validation flow, CAA checking, and the controls that would prevent recurrence. Izenpe later said it removed the alternative request path, enabled additional subject/SAN checks, revoked four certificates that had been validated using the manual path, and integrated the web application with the PKI system so issuance is now automated and the CSR is rebuilt from validated data. The bug was resolved as FIXED, and Mozilla later indicated the matter appeared adequately addressed.

Model: gpt-5.4-mini Generated: 2026-06-13 21:11 UTC Revised: 2026-06-16 19:13 UTC Confidence: 0.96 32 comments
Chronology
  1. Izenpe detected a certificate issued for an internal domain and revoked the affected certificate.
  2. Izenpe stopped allowing certificate requests through the manual alternative path and required use of the web application.
  3. Izenpe re-enabled subject/SAN checks in its PKI software.
  4. Izenpe revoked four certificates that had been processed through the manual validation path.
  5. Izenpe said the web application and PKI system integration was in production.
Thread Activity
  1. Izenpe S.A. — Izenpe opened the bug and reported that internal monitoring found one misissued certificate, which had already been revoked.
  2. Community commenter — Mozilla asked for a more complete incident report, including how the failure happened and what controls would prevent unvalidated issuance.
  3. Izenpe S.A. — Izenpe described a manual contingency process, listed four affected certificates, and said it had required customers to use the web application.
  4. Izenpe S.A. — Izenpe explained the validation methods used for the four certificates and said the misissued certificate resulted from using the wrong CSR.
  5. Izenpe S.A. — Izenpe said it had used Google dig for CAA lookups, acknowledged that this was third-party software, and revoked the four affected certificates.
  6. Izenpe S.A. — Izenpe said the integration with the PKI system was in production and that validations were now automated.
  7. Mozilla representative — Mozilla said it was inclined to close the matter as adequately addressed.
Participants
Izenpe S.A. Community commenter Mozilla representative Mm representative Fozzie representative
Similar Local Cases
#1559765 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-06-17 · Closed 2023-02-22 · 100% similar
Izenpe: Multiple invalid EV certificates issued
#1391054 RESOLVED Ca Certificate Compliance Incident Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 91% similar
Izenpe: Non-BR-Compliant Certificate Issuance
#1876565 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-01-25 · Closed 2024-04-06 · 89% similar
Izenpe: Not allowed Qualifier ID OID on Certificate Policies extension
#1921254 RESOLVED Certificate Misissuance Self Reported Incident Opened 2024-09-26 · Closed 2025-02-19 · 89% similar
Izenpe: Duplicate attribute in Subject
#1712188 RESOLVED Certificate Misissuance Opened 2021-05-20 · Closed 2023-02-22 · 88% similar
Sectigo: test certificates issued from trusted CA
#1705187 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-04-14 · Closed 2023-02-22 · 87% similar
KIR S.A.: CN domain not in SAN
#1945867 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-02-04 · Closed 2025-04-18 · 87% similar
Izenpe: Incorrect Unicode characters in Subject
#1717357 RESOLVED Certificate Misissuance Incident Opened 2021-06-20 · Closed 2023-02-22 · 86% similar
Actalis: Issuance of intermediates after 2020-08-20 that do not comply with Mozilla Policy and the Baseline Requirements

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action