Izenpe: Multiple sub CAs with incorrectly encoded SubjectPublicKeyInfo algorithm
This case reports that multiple Izenpe-issued sub CAs under the “Izenpe.com” root contain an incorrectly encoded algorithm in their SubjectPublicKeyInfo structure. The thread states that because the algorithm is sha256WithRSAEncryption, the parameters field must contain ASN.1 NULL per RFC 4055, but the parameters are omitted. The reporter lists several affected sub CAs and provides crt.sh links for each. Izenpe responded that it was analyzing the issue with its PKI software provider and would publish details as soon as possible. Izenpe also stated that the affected sub CAs were issued in October 2010, before BR 1.0 (effective 1 July 2012), and that sub CAs issued after BR 1.0 have the correct signature parameters. The bug was then closed as a duplicate of Bug 1667846.
- Bug 1685767 was filed reporting incorrectly encoded SubjectPublicKeyInfo algorithm parameters in multiple Izenpe sub CAs under the Izenpe.com root.
- Izenpe began analyzing the issue with its PKI software provider and indicated it would publish details.
- Izenpe provided context about issuance timing relative to BR 1.0 and described roadmap items for sub-CA handling.
- Mozilla indicated an intent to close the bug as a duplicate of Bug 1667846.
- Bug 1685767 was marked as a duplicate of Bug 1667846.
- Community commenter — Reported that several Izenpe sub CAs have SubjectPublicKeyInfo algorithm parameters omitted despite sha256WithRSAEncryption requiring ASN.1 NULL per RFC 4055, and listed affected sub CAs with crt.sh links.
- Izenpe S.A. — Said Izenpe was analyzing the issue with its PKI software provider and would publish details soon.
- Izenpe S.A. — Linked the issue to Bug 1667846, stated the affected sub CAs were issued in October 2010 before BR 1.0, and described roadmap plans including a new CA tree and planned renovation to include the NULL parameter.
- Mozilla representative — Indicated intent to close this bug as a duplicate of Bug 1667846.
- Mozilla representative — Marked the bug as a duplicate of Bug 1667846.