← Disig, a.s. cases
Bugzilla #1670458 Policy Compliance

Disig: Failure to provide a preliminary report within 24 hours.

RESOLVED FIXED Disig, a.s.
AI Summary

Disig, a.s. faced a compliance issue for failing to provide a preliminary report within the required 24-hour timeframe after receiving a problem report regarding misissued certificates. The issue arose when a report was sent on October 10, 2020, but Disig did not respond until October 12, 2020, citing a low security risk and weekend timing as reasons for the delay. The CA has since acknowledged the oversight and has taken steps to improve their incident response processes. They have also committed to revoking the misissued certificates and have updated their certificate issuance profiles to prevent similar issues in the future.

Model: gpt-4o-mini Generated: 2026-06-13 21:19 UTC Confidence: 0.90
Chronology
  1. Problem report received by Disig.
  2. Disig responded to the report, acknowledging the delay.
  3. Disig issued new certificates without the problematic field.
  4. All misissued certificates were revoked.
Participants
George [:fozzie] Peter Miskovic
External References
Similar Local Cases
#1717001 RESOLVED Policy Compliance Opened 2021-06-17 · Closed 2022-11-14 · 66% similar
Disig: CPS does not refer to BR domain validation methods
#1700809 RESOLVED Policy Compliance Opened 2021-03-25 · Closed 2023-02-22 · 45% similar
Microsoft PKI Services: Failure to disclose Unconstrained Intermediate within 7 Days
#2013400 RESOLVED Policy Compliance Opened 2026-01-29 · Closed 2026-04-17 · 44% similar
NETLOCK: did not file a preliminary incident report or respond to a third-party report within the 72-hour timeframe
#1625715 RESOLVED Policy Compliance Opened 2020-03-29 · Closed 2023-02-22 · 43% similar
Sectigo: Failure to revoke certificate with previously-compromised key within 24 hours
#1390974 RESOLVED Policy Compliance Opened 2017-08-16 · Closed 2023-02-22 · 43% similar
Actalis: Non-BR-Compliant Certificate Issuance
#1680378 RESOLVED Policy Compliance Opened 2020-12-02 · Closed 2023-02-22 · 42% similar
NetLock: Replacement of enduser certificates after the EVGL 1.7.4 self-audit
#1693930 RESOLVED Policy Compliance Opened 2021-02-20 · Closed 2023-02-22 · 42% similar
Microsoft PKI Services: Policy Documentation, Failure to update Subscriber Certificate Max Validity Period
#1817023 RESOLVED Policy Compliance Opened 2023-02-15 · Closed 2024-05-09 · 42% similar
Microsoft PKI Services: Failure to modify policy documents within 365 days

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action