← DigiCert cases
Bugzilla #1654967
Self Incident Disclosure
DigiCert: Malformed ICA
RESOLVED
DigiCert
AI Summary
DigiCert reported a significant incident involving the issuance of intermediate CA certificates that did not comply with Mozilla's baseline requirements. The issue was identified during a post-issuance review, revealing that several ICAs lacked necessary extensions and contained improper profiles. Following the discovery, DigiCert halted all new certificate ceremonies until automation improvements were implemented to prevent future occurrences.
Chronology
- Incident reported and initial investigation began.
- Additional checks and improvements to ICA process discussed.
- Updated incident report requested.
- Public Key Ceremony completed with new automation tool.
Participants
Martin Sullivan
Jeremy Rowley
Ryan Sleevi
Rob Stradling
External References
Similar Local Cases
Sectigo Self-Assessments of CP/CPS and BR Compliance
DigiCert: Incorrect OCSP Delegated Responder Certificate
Izenpe: Failure to Submit Annual CCADB Self-Assessment
NCSSR Self-assessment Swiss BIT, Swiss Federal Office of Information Technology, Systems and Telecommunication (FOITT)
SSL.com CCADB Self Assessment 2024
SSL.com CCADB Self Assessment 2025
NAVER Cloud Trust Services CCADB Self Assessment 2023
NAVER Cloud Trust Services CCADB Self Assessment 2023