← Izenpe S.A. cases
Bugzilla #1685767 Ca Certificate Compliance

Izenpe: Multiple sub CAs with incorrectly encoded SubjectPublicKeyInfo algorithm

RESOLVED (DUPLICATE) DUPLICATE Izenpe S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case reports that multiple Izenpe-issued sub CAs under the “Izenpe.com” root contain an incorrectly encoded algorithm in their SubjectPublicKeyInfo structure. The thread states that because the algorithm is sha256WithRSAEncryption, the parameters field must contain ASN.1 NULL per RFC 4055, but the parameters are omitted. The reporter lists several affected sub CAs and provides crt.sh links for each. Izenpe responded that it was analyzing the issue with its PKI software provider and would publish details as soon as possible. Izenpe also stated that the affected sub CAs were issued in October 2010, before BR 1.0 (effective 1 July 2012), and that sub CAs issued after BR 1.0 have the correct signature parameters. The bug was then closed as a duplicate of Bug 1667846.

Model: gpt-5.4-nano Generated: 2026-06-13 21:13 UTC Revised: 2026-06-16 19:14 UTC Confidence: 0.86 5 comments
Chronology
  1. Bug 1685767 was filed reporting incorrectly encoded SubjectPublicKeyInfo algorithm parameters in multiple Izenpe sub CAs under the Izenpe.com root.
  2. Izenpe began analyzing the issue with its PKI software provider and indicated it would publish details.
  3. Izenpe provided context about issuance timing relative to BR 1.0 and described roadmap items for sub-CA handling.
  4. Mozilla indicated an intent to close the bug as a duplicate of Bug 1667846.
  5. Bug 1685767 was marked as a duplicate of Bug 1667846.
Thread Activity
  1. Community commenter — Reported that several Izenpe sub CAs have SubjectPublicKeyInfo algorithm parameters omitted despite sha256WithRSAEncryption requiring ASN.1 NULL per RFC 4055, and listed affected sub CAs with crt.sh links.
  2. Izenpe S.A. — Said Izenpe was analyzing the issue with its PKI software provider and would publish details soon.
  3. Izenpe S.A. — Linked the issue to Bug 1667846, stated the affected sub CAs were issued in October 2010 before BR 1.0, and described roadmap plans including a new CA tree and planned renovation to include the NULL parameter.
  4. Mozilla representative — Indicated intent to close this bug as a duplicate of Bug 1667846.
  5. Mozilla representative — Marked the bug as a duplicate of Bug 1667846.
Participants
Community commenter Izenpe S.A. Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1559765 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-06-17 · Closed 2023-02-22 · 74% similar
Izenpe: Multiple invalid EV certificates issued
#1793441 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-10-03 · Closed 2023-02-22 · 67% similar
GlobalSign: CRL contains invalid signature algorithm
#1918427 RESOLVED Ca Certificate Compliance Incident Closure Request Opened 2024-09-12 · Closed 2024-10-11 · 67% similar
D-Trust: Non-compliance of issued root and intermediate S/MIME certificates
#1710856 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-05-12 · Closed 2023-02-22 · 66% similar
DigiCert: Invalid localityName
#1705657 RESOLVED Ca Certificate Compliance Revocation Issue Opened 2021-04-16 · Closed 2023-02-22 · 66% similar
KIR S.A.: Many certificates with OCSP Unknown
#1267049 RESOLVED Certificate Misissuance Opened 2016-04-24 · Closed 2023-02-22 · 66% similar
Izenpe: EV certificate with various issues
#1942130 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2025-01-16 · Closed 2025-05-01 · 66% similar
HARICA: S/MIME certificate issuance without proper validation
#1815534 RESOLVED Ca Certificate Compliance Certificate Misissuance Revocation Issue Opened 2023-02-07 · Closed 2024-04-17 · 66% similar
e-commerce monitoring GmbH: SCT in precertificate

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action