← D-TRUST cases
Bugzilla #1691117 Ca Certificate Compliance Certificate Misissuance Closure Request

D-TRUST: Certificate with RSA key where modulus is not divisible by 8

RESOLVED FIXED D-TRUST
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case is a preliminary and then final incident report from D-TRUST about a certificate whose RSA key did not comply with the Mozilla Root Store Policy and the CA/Browser Forum Baseline Requirements. D-TRUST stated it was informed by a third party about the issue via D-TRUST’s Incident Report Mechanism. D-TRUST reported that the affected certificate was issued on 2019-02-14 and that it was issued through D-TRUST’s retail customer application processing system, which D-TRUST said was shut down for good on 2019-07-19. D-TRUST said it revoked the affected certificate within the timeframe specified by BR and performed analysis across all databases to ensure no valid certificate exists with an RSA key size not divisible by 8. D-TRUST also stated it re-examined technical measures to prevent issuance of such TLS certificates and adapted specification documents so future analyses must be carried out on all TLS databases containing at least one still-valid TLS certificate. Mozilla indicated it intended to close the matter on 10-Mar-2021, and the bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:21 UTC Revised: 2026-06-16 18:39 UTC Confidence: 0.86 7 comments
Chronology
  1. D-TRUST issued a TLS certificate whose RSA key modulus was not divisible by 8.
  2. D-TRUST shut down its retail-customer application processing system for good.
  3. D-TRUST began investigating the reported non-compliant certificate and its issuance circumstances.
  4. D-TRUST revoked the affected certificate.
  5. D-TRUST published its final incident report after completing thorough analysis.
  6. Mozilla indicated it intended to close the matter.
Thread Activity
  1. Bdr representative — Opened a preliminary incident report stating D-TRUST was informed via its Incident Report Mechanism that it had issued a certificate with an RSA key not complying with Mozilla Root Store Policy and CA/Browser Forum Baseline Requirements, and provided an investigation timeline and planned revocation.
  2. Thisisntrocket representative — Asked for clarification on whether D-TRUST had checked its current valid certificate corpus or whether it would only avoid signing new certificates with the same problem.
  3. Bdr representative — Explained that the affected certificate was issued via D-TRUST’s retail-customer application processing system, which was shut down for good on 19/07/2019, and stated that Managed PKI is now the only system for issuing TLS certificates.
  4. Bdr representative — Posted the final incident report, including a detailed explanation of how the issue was not detected in internal analysis due to a misunderstanding limited to the currently used Managed PKI platform, and listed remedial steps including revocation and technical/documentation changes.
  5. Mozilla representative — Asked whether there is a pre-issuance check ensuring future RSA key sizes are divisible by 8 and when adapted specification documents would be implemented.
  6. Bdr representative — Described existing pre-issuance checks (accepting only RSA key sizes 2048/3072/4096 and linting based on ZLint before CT logging) and clarified that documentation changes were already made.
  7. Mozilla representative — Stated the matter can be closed and intended to close it on Wed. 10-Mar-2021.
Participants
Bdr representative Thisisntrocket representative Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1682270 RESOLVED Ca Certificate Compliance Incident Closure Request Opened 2020-12-14 · Closed 2026-06-12 · 100% similar
D-TRUST: Private Key Disclosed by Customer as Part of CSR
#1924385 RESOLVED Ca Certificate Compliance Revocation Issue Closure Request Opened 2024-10-13 · Closed 2025-07-16 · 100% similar
D-Trust: Missed Revocation of TLS certificates affected by Bugzilla 1884714
#1939809 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-01-03 · Closed 2026-06-12 · 100% similar
D-Trust: QCStatement with http link of PKI Disclosure Statements
#1896190 RESOLVED Ca Certificate Compliance Opened 2024-05-10 · Closed 2024-11-06 · 99% similar
D-Trust: Issuance of an EV certificate containing a mixup of the Subject's postalCode and localityName
#1610303 RESOLVED Ca Certificate Compliance Opened 2020-01-20 · Closed 2023-02-22 · 97% similar
D-TRUST: Issuance of non-conformant SSL certificate
#1647468 RESOLVED Ca Certificate Compliance Opened 2020-06-22 · Closed 2023-02-22 · 97% similar
D-TRUST: Wrong key usage (Key Encipherment)
#1793440 RESOLVED Self Reported Incident Certificate Misissuance Opened 2022-10-03 · Closed 2023-02-22 · 96% similar
D-TRUST: CRL not DER-encoded
#1756122 RESOLVED Self Reported Incident Certificate Misissuance Opened 2022-02-18 · Closed 2023-02-22 · 95% similar
D-TRUST: Wrong key usage (Key Agreement)

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action