← Krajowa Izba Rozliczeniowa S.A. (KIR) cases
Bugzilla #1708965 Certificate Misissuance

KIR S.A.: Certificates issued with validity period 1 second longer than stated in CPS

RESOLVED FIXED Krajowa Izba Rozliczeniowa S.A. (KIR)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

KIR S.A. reported that it issued certificates whose validity period was 1 second longer than the validity period stated in its Certification Practice Statement (CPS) section 6.3.2. The issue was triggered by KIR’s CPS v1.12 update published on 2020-09-01, where KIR failed to consider the RFC 5280 inclusive validity period definition (from notBefore through notAfter, inclusive). KIR stated that while the issued certificates’ validity periods were compliant with the BR, the CPS description was imprecise because it did not include the inclusive requirement. KIR said it stopped issuing certificates with the problem and identified about 300 affected certificates issued between 2020-09-17 and 2021-04-28. KIR also stated it replaced the affected certificates ASAP, noting that about 50 would be replaced within two weeks and the remaining 261 would be replaced sooner than 7 months, with some client actions needed due to use in closed banking systems. Mozilla indicated that this bug could be closed and that further tracking, if needed, could be done under other Bugzilla IDs related to delayed revocation and CPS noncompliance. The bug is resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:13 UTC Revised: 2026-06-16 19:13 UTC Confidence: 0.86 7 comments
Chronology
  1. KIR updated its BR/CPS materials, and KIR later stated it failed to consider the RFC 5280 inclusive validity period definition.
  2. KIR’s CPS review period ended and KIR identified certificates issued with the 1-second-longer validity period up to this date.
  3. KIR filed the incident report describing certificates issued with validity periods 1 second longer than stated in its CPS.
  4. Mozilla scheduled closure of the bug, with potential follow-up tracking under other Bugzilla IDs.
Thread Activity
  1. Kir representative — KIR described the issue: certificates had validity periods 1 second longer than stated in CPS, explained the RFC 5280 inclusive validity period cause, listed affected issuance dates and an estimated count (~300), and stated it stopped issuing the problematic certificates and began replacements ASAP.
  2. Kir representative — KIR clarified that it did not issue certificates greater than 398 days, but rather 1 year plus 1 second.
  3. Community commenter — Ryan Sleevi criticized the incident report as not meeting incident-report requirements and asked for more complete root-cause and remediation details.
  4. Jesperkristensen representative — Jesper Kristensen asked about whether CPS precision should be assumed similarly to BR precision, noting difficulty finding the older CPS version.
  5. Kir representative — KIR provided a link to an archived CPS PDF referenced in response to the CPS-precision question.
  6. Kir representative — KIR responded to the incident-report critique, described replacement timing constraints (closed banking systems), and reiterated replacement plans for affected certificates.
  7. Mozilla representative — Mozilla stated the bug could be closed and that further tracking could be done under Bugzilla #1709872 or #1705904, scheduling closure for 11-June-2021.
Participants
Kir representative Community commenter Jesperkristensen representative Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1921597 RESOLVED Certificate Misissuance Opened 2024-09-28 · Closed 2025-02-19 · 96% similar
KIR: Intermediate CA - SZAFIR Trusted CA4 - Certificate Policies extension - non-compliance
#1921598 RESOLVED Certificate Misissuance Opened 2024-09-28 · Closed 2025-02-19 · 94% similar
KIR: Intermediate CA - SZAFIR Trusted CA3 - Certificate Policies extension - non-compliance
#1705187 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-04-14 · Closed 2023-02-22 · 84% similar
KIR S.A.: CN domain not in SAN
#1705647 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-04-16 · Closed 2023-02-22 · 84% similar
KIR S.A.: Invalid organizationName
#1654216 RESOLVED Certificate Misissuance Opened 2020-07-21 · Closed 2023-02-22 · 78% similar
Buypass: PSD2 QWAC with RSA modulus not divisible by 8
#1667518 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-09-26 · Closed 2023-02-22 · 77% similar
QuoVadis: Incorrect keyUsage for ECC certificate
#1760311 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-03-18 · Closed 2023-02-22 · 77% similar
GlobalSign: OCSP responder certificates with more than 64 characters in CN
#1669594 RESOLVED Certificate Misissuance Opened 2020-10-06 · Closed 2023-02-22 · 77% similar
IdenTrust: Issuance of Subordinate CA’s Without EKU

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action