Izenpe: Certificates not disclosed in CCADB
The bug was opened because crt.sh/mozilla-disclosures reported that an Izenpe certificate was not disclosed in the Common CA Database (CCADB). The report included a specific certificate serial number and issuer/subject details for a certificate issued by the Izenpe CA. A Mozilla commenter suggested the issue might be related to a “NULL” bit/signature parameter creating a second SHA2 hash for an already known/disclosed CA certificate. The reporter confirmed that searching the CCADB for the serial number did find the disclosed certificate. A Sectigo commenter explained that the “NULL” signature parameters were actually correct for an RSA signature, but that the TBSCertificate signature parameters were missing required “NULL” parameters, implying the crt.sh flag was likely due to a duplicate/record mismatch rather than a true CCADB disclosure failure. The reporter stated it appeared to be a false positive and closed the bug as INVALID, while encouraging Izenpe to consider replacing older long-lived intermediate certificates with newer BR-compliant certificates. The thread also notes that Bug 1685767 was marked as a duplicate of this bug.
- A crt.sh/mozilla-disclosures report flagged an Izenpe certificate as not disclosed in CCADB.
- The reporter checked CCADB and found the certificate disclosed for the reported serial number.
- A third party removed a duplicate certificate record from crt.sh to stop the flagging.
- The bug was closed as INVALID as a false positive.
- Bug 1685767 was marked as a duplicate of this bug.
- Mozilla representative — Reported that crt.sh/mozilla-disclosures flagged a specific Izenpe certificate as not disclosed in CCADB and provided the certificate details and links.
- Mozilla representative — Suggested the flag may be caused by adding a “NULL” bit to create a second SHA2 hash for an already disclosed CA certificate.
- Mozilla representative — Confirmed that searching CCADB for the serial number finds the disclosed certificate.
- Sectigo — Explained that “NULL” signature parameters are correct for RSA, but missing required “NULL” parameters in TBSCertificate likely caused the crt.sh misflag; stated a duplicate crt.sh record was deleted to stop the flagging.
- Mozilla representative — Concluded it was a false positive, closed as INVALID, and encouraged Izenpe to consider replacing old long-lived intermediate certs with newer BR-compliant certs.
- Izenpe S.A. — Acknowledged the suggestion and said they would keep it in mind.
- Mozilla representative — Noted that Bug 1685767 was marked as a duplicate of this bug.