← Certigna cases
Bugzilla #1667744 Self Reported Incident

Dhimyotis / Certigna: Certificates issued with validity periods greater than 398-days

RESOLVED FIXED Certigna
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case involves Dhimyotis/Certigna, which issued certificates with validity periods exceeding the 398-day limit mandated by the Baseline Requirements. The issue was identified internally, and the CA acknowledged a configuration error that resulted in the issuance of certificates with a duration of 398 days and 1 second. Following the discovery, Certigna promptly updated its certificate generation service to prevent future occurrences and initiated the revocation of the affected certificates. By October 26, 2020, all non-compliant certificates had been revoked, and the CA committed to improving its practices to ensure compliance with the validity period requirements.

Model: gpt-4o-mini Generated: 2026-06-13 21:22 UTC Revised: 2026-06-16 18:21 UTC Confidence: 0.90 13 comments
Chronology
  1. Dhimyotis/Certigna identified and acknowledged the issuance of non-compliant certificates.
  2. All affected certificates were revoked.
Thread Activity
  1. Sectigo — Reported that Certigna issued certificates with validity periods greater than 398 days.
  2. Dhimyotis representative — Acknowledged the issue and promised a consolidated response.
  3. Certigna — Confirmed the issuance of non-compliant certificates due to a configuration error.
  4. Dhimyotis representative — Confirmed initiation of the revocation process for the affected certificates.
  5. Dhimyotis representative — Informed that all affected certificates have been revoked.
Participants
Sectigo Dhimyotis representative Certigna Community commenter Mozilla representative
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#1973032 RESOLVED Self Reported Incident Opened 2025-06-19 · Closed 2025-07-02 · 94% similar
Certigna: Finding #2 ETSI Audit - Risks regarding the certification of device not described
#1973034 RESOLVED Self Reported Incident Opened 2025-06-19 · Closed 2025-07-02 · 94% similar
Certigna: Finding #3 ETSI Audit – Event log protection beyond seven years shall be improved
#2041368 RESOLVED Self Reported Incident Opened 2026-05-21 · Closed 2026-06-02 · 87% similar
Certigna: Finding #1 ETSI Audit – Missing system configuration information in the CP/CPS
#1690807 RESOLVED Incident Self Reported Incident Opened 2021-02-04 · Closed 2023-02-22 · 86% similar
GlobalSign: RSA-1024 leaf certificate issued after 2013-12-31
#1664328 RESOLVED Incident Self Reported Incident Opened 2020-09-10 · Closed 2023-02-22 · 86% similar
GlobalSign: SHA-256 hash algorithm used with ECC P-384 key
#2043140 RESOLVED Self Reported Incident Opened 2026-05-28 · Closed 2026-06-16 · 86% similar
Certigna: Delay in reporting an audit finding
#1654967 RESOLVED Self Reported Incident Revocation Issue Opened 2020-07-24 · Closed 2023-02-22 · 83% similar
DigiCert: Malformed ICA
#1718771 RESOLVED Self Reported Incident Revocation Issue Opened 2021-06-30 · Closed 2023-02-22 · 83% similar
Sectigo: DCV Reuse after 825 days

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action