← e-tugra cases
Bugzilla #1716843 Incident

E-Tugra: Intermediate CA Certificate Missing from Audit Reports

RESOLVED FIXED e-tugra
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

E-Tugra disclosed a compliance issue regarding the omission of the intermediate CA certificate 'E-Tuğra Nitelikli Elektronik Sertifika Hizmet Sağlayıcısı v2' from their audit reports. The CA acknowledged that this intermediate CA was capable of issuing TLS certificates, which raised concerns about its compliance with Mozilla's policies and the CA/Browser Forum Baseline Requirements. E-Tugra committed to including this CA in future audits and has initiated a revocation plan for the certificate, which was ultimately revoked on January 19, 2022. The CA has also been added to Mozilla's OneCRL to mitigate risks associated with its previous compliance failures.

Model: gpt-4o-mini Generated: 2026-06-13 21:24 UTC Revised: 2026-06-16 18:38 UTC Confidence: 0.90 21 comments
Chronology
  1. The intermediate CA was revoked.
Thread Activity
  1. Mozilla representative — E-Tugra's audit report does not list the intermediate CA certificate.
  2. E-Tugra — E-Tugra confirmed the CA is used for end entity certificates and will include it in future audits.
  3. Community commenter — Concerns were raised about E-Tugra's compliance with the Baseline Requirements.
  4. E-Tugra — E-Tugra outlined steps to revoke the intermediate CA and ensure compliance.
  5. E-Tugra — The intermediate CA was revoked.
Participants
Mozilla representative E-Tugra Community commenter
External References
Similar Local Cases
#1716902 RESOLVED Incident Opened 2021-06-17 · Closed 2023-02-22 · 100% similar
E-Tugra: Forbidden Domain Validation Method 3.2.2.4.6
#1772414 RESOLVED Incident Opened 2022-06-02 · Closed 2023-02-22 · 93% similar
E-Tugra: Failure to Respond to May 2022 Survey
#1593776 RESOLVED Ca Certificate Compliance Incident Opened 2019-11-04 · Closed 2023-02-22 · 78% similar
Sectigo: invalid subject:organizationalUnitName on DV certificates
#1717357 RESOLVED Certificate Misissuance Incident Opened 2021-06-20 · Closed 2023-02-22 · 78% similar
Actalis: Issuance of intermediates after 2020-08-20 that do not comply with Mozilla Policy and the Baseline Requirements
#1690807 RESOLVED Incident Self Reported Incident Opened 2021-02-04 · Closed 2023-02-22 · 77% similar
GlobalSign: RSA-1024 leaf certificate issued after 2013-12-31
#1688215 RESOLVED Ca Documents Incident Policy Document Issue Opened 2021-01-22 · Closed 2023-02-22 · 76% similar
Camerfirma: CP/CPS of Intesa Sanpaolo Sub-CA is Non-Compliant
#1717795 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Opened 2021-06-23 · Closed 2023-02-22 · 76% similar
Firmaprofesional: 2021 Audit Report Finding 3 out of 3
#1705832 RESOLVED Incident Self Reported Incident Opened 2021-04-16 · Closed 2023-02-22 · 75% similar
KIR S.A.: DV certificates with locality name, organization name and stateOrProvinceName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action