← DigiCert cases
Bugzilla #1664325 Ca Certificate Compliance

DigiCert: SHA-256 hash algorithm used with ECC P-384 key

RESOLVED DUPLICATE DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The bug was raised because a certificate (OCSP) was reported to be signed using an ECC P-384 key while using ECDSA with SHA-256, contrary to the Mozilla policy requirement that P-384 signing keys must use ECDSA with SHA-384. The reporter cited Mozilla policy text and referenced a crt.sh entry for the certificate. DigiCert stated that the issue was already disclosed in another Bugzilla issue and requested that this bug be closed as a duplicate. The bug was subsequently marked as a duplicate of bug 1654967. The reporter later apologized for the duplicate and explained they had not found the original bug initially.

Model: gpt-5.4-nano Generated: 2026-06-13 11:39 UTC Revised: 2026-06-16 19:05 UTC Confidence: 0.86 4 comments
Chronology
  1. A report was filed alleging an OCSP signature used ECDSA with SHA-256 despite being produced with an ECC P-384 key.
  2. The CA indicated the issue was already disclosed in an existing bug and the case was marked as a duplicate.
Thread Activity
  1. Sectigo — The reporter cited Mozilla policy and said the OCSP signature uses ECDSA with SHA-256 even though it is signed by a P-384 key, noting it appeared to repeat Bug 1527423.
  2. DigiCert — Digicert stated the issue was already disclosed in bug 1654967 and asked to close this bug as a duplicate.
  3. Community commenter — The commenter acknowledged the duplicate and noted the bug was marked as a duplicate of bug 1654967.
  4. Sectigo — The reporter apologized and said they later found the original bug after searching Bugzilla more thoroughly.
Participants
Sectigo DigiCert Community commenter
Related Bugzilla IDs Mentioned
Similar Local Cases
#1710856 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-05-12 · Closed 2023-02-22 · 94% similar
DigiCert: Invalid localityName
#1675923 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-11-07 · Closed 2024-05-09 · 86% similar
DigiCert: TERENA: Insufficient validation of organizationalUnitName
#1262610 RESOLVED Ca Certificate Compliance Opened 2016-04-06 · Closed 2023-02-22 · 86% similar
DigiCert: ECCE 001 issuing certificates without subject alternative name extension
#1714439 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2021-06-03 · Closed 2023-02-22 · 82% similar
DigiCert: Incorrect RegNumber-Org Type combination
#2032485 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-04-16 · Closed 2026-05-04 · 80% similar
DigiCert: Misissuance detected by PKIMetal
#2007219 RESOLVED Ca Certificate Compliance Opened 2025-12-20 · Closed 2026-02-17 · 78% similar
DigiCert: Some certificates issued with CRLDPs that don’t exactly match CCADB disclosures
#2015186 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-02-06 · Closed 2026-03-23 · 77% similar
DigiCert: Subject Serial Numbers for Non-Commercial Entities
#1759122 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-03-11 · Closed 2022-11-14 · 76% similar
DigiCert: EV for Onion addresses without Tor Service Descriptor

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action