Dhimyotis / Certigna: Certificates issued with validity periods greater than 398-days
Certigna (Dhimyotis) reported a non-compliance involving 76 certificates and pre-certificates issued between September 1 and September 28, 2020 with a fixed lifetime of 398 days, which it stated did not take into account the second inclusive. The non-compliance was identified and escalated on September 28, 2020, and on September 29, 2020 Certigna notified its French supervisory body (ANSSI) of the non-compliance and its intention to revoke the affected certificates. Certigna stated it attempted to comply with the 5-day revocation delay but that many remaining certificates were already deployed on government teleservices, where revocation would have impacted services sometimes managed by external providers. Certigna provided a revocation history showing that while some certificates were revoked before October 2, others were revoked later (e.g., before D+10, before D+25). Certigna corrected its certificate profiles on September 29 to ensure certificate lifespan would not exceed 397 days, and it discussed with ANSSI circumstances that could lead to revocation delays. The thread also includes discussion that an incident report was not correctly written initially, with Certigna providing a more complete incident report and timeline; Mozilla indicated it appeared the certificates were revoked and that discussion for future reference was adequate, intending to close unless additional items remained. The bug is marked RESOLVED with resolution FIXED.
- Certigna identified and escalated a non-compliance involving certificate validity periods set to 398 days.
- Certigna notified ANSSI and initiated revocation actions for affected certificates.
- Some of the remaining affected certificates were revoked around this date, following the initial escalation.
- Certigna’s qualification audit occurred (Oct 2–8, 2020) during which the supervisory body observed the handling of the issue.
- Mozilla indicated it intended to close the bug on or about 5-Mar-2021 unless additional items remained.
- Certigna — Certigna described the 398-day validity non-compliance, the notification to ANSSI, the revocation history for 76 affected certificates/pre-certificates, and remediation steps including profile corrections and additional checks.
- Community commenter — Mozilla marked bug 1685142 as a duplicate of this bug.
- Community commenter — A commenter questioned how Certigna’s stated training/remediation would prevent the issue, arguing that revocation delays and incident reporting expectations were not met.
- Certigna — Certigna responded that the incident report was not correctly written and provided a more complete report including how the CA became aware, a timeline, and details about issuance and revocation.
- Certigna — Certigna created an attachment listing revoked certificates (list-cert-revoked.xlsx).
- Mozilla representative — Mozilla stated it appeared the certificates were revoked and that discussion for future reference was adequate, intending to close unless additional items remained.