← Izenpe S.A. cases
Bugzilla #1667846 Ca Documents Incident

Izenpe: Certificates not disclosed in CCADB

RESOLVED INVALID Izenpe S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The bug was opened because crt.sh/mozilla-disclosures reported that an Izenpe certificate was not disclosed in the Common CA Database (CCADB). The report included a specific certificate serial number and issuer/subject details for a certificate issued by the Izenpe CA. A Mozilla commenter suggested the issue might be related to a “NULL” bit/signature parameter creating a second SHA2 hash for an already known/disclosed CA certificate. The reporter confirmed that searching the CCADB for the serial number did find the disclosed certificate. A Sectigo commenter explained that the “NULL” signature parameters were actually correct for an RSA signature, but that the TBSCertificate signature parameters were missing required “NULL” parameters, implying the crt.sh flag was likely due to a duplicate/record mismatch rather than a true CCADB disclosure failure. The reporter stated it appeared to be a false positive and closed the bug as INVALID, while encouraging Izenpe to consider replacing older long-lived intermediate certificates with newer BR-compliant certificates. The thread also notes that Bug 1685767 was marked as a duplicate of this bug.

Model: gpt-5.4-nano Generated: 2026-06-13 21:12 UTC Revised: 2026-06-16 19:14 UTC Confidence: 0.86 7 comments
Chronology
  1. A crt.sh/mozilla-disclosures report flagged an Izenpe certificate as not disclosed in CCADB.
  2. The reporter checked CCADB and found the certificate disclosed for the reported serial number.
  3. A third party removed a duplicate certificate record from crt.sh to stop the flagging.
  4. The bug was closed as INVALID as a false positive.
  5. Bug 1685767 was marked as a duplicate of this bug.
Thread Activity
  1. Mozilla representative — Reported that crt.sh/mozilla-disclosures flagged a specific Izenpe certificate as not disclosed in CCADB and provided the certificate details and links.
  2. Mozilla representative — Suggested the flag may be caused by adding a “NULL” bit to create a second SHA2 hash for an already disclosed CA certificate.
  3. Mozilla representative — Confirmed that searching CCADB for the serial number finds the disclosed certificate.
  4. Sectigo — Explained that “NULL” signature parameters are correct for RSA, but missing required “NULL” parameters in TBSCertificate likely caused the crt.sh misflag; stated a duplicate crt.sh record was deleted to stop the flagging.
  5. Mozilla representative — Concluded it was a false positive, closed as INVALID, and encouraged Izenpe to consider replacing old long-lived intermediate certs with newer BR-compliant certs.
  6. Izenpe S.A. — Acknowledged the suggestion and said they would keep it in mind.
  7. Mozilla representative — Noted that Bug 1685767 was marked as a duplicate of this bug.
Participants
Mozilla representative Sectigo Izenpe S.A.
Related Bugzilla IDs Mentioned
Similar Local Cases
#1667844 RESOLVED Ca Documents Opened 2020-09-28 · Closed 2023-02-22 · 83% similar
Google Trust Services: Certificates not disclosed in CCADB
#1941675 RESOLVED Ca Documents Incident Opened 2025-01-14 · 76% similar
Certum root lists a Microsec CPS in AllCertificateRecordsCSVFormatv2
#1267049 RESOLVED Certificate Misissuance Opened 2016-04-24 · Closed 2023-02-22 · 75% similar
Izenpe: EV certificate with various issues
#1597947 RESOLVED Ca Certificate Compliance Incident Opened 2019-11-20 · Closed 2023-02-22 · 74% similar
Sectigo: CCADB failed ALV - Network Solutions Certificate Authority
#1651026 RESOLVED Certificate Misissuance Incident Remediation Tracking Opened 2020-07-07 · Closed 2023-02-22 · 74% similar
Izenpe: certificate issued to internal domain
#1626805 RESOLVED Ca Documents Audit Finding Opened 2020-04-01 · Closed 2023-02-22 · 72% similar
FNMT: Minor non-conformities in 2020 audit statement
#1496616 RESOLVED Ca Documents Opened 2018-10-04 · Closed 2023-02-22 · 72% similar
Consorci AOC: Qualified audit statements
#1969842 RESOLVED Ca Documents Incident Opened 2025-06-02 · Closed 2025-07-16 · 68% similar
ANF AC: Finding #1 ETSI Audit - Missing log retention period in Terms and Conditions v1.9

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action