← Izenpe S.A. cases
Bugzilla #1738421 Self Reported Incident Audit Finding

Izenpe: CRL and ARL exceed validity period value by one second

RESOLVED FIXED Izenpe S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Izenpe reported that its CRL and Root certificate ARL validity periods exceeded the intended duration by one second, which it stated did not comply with BR 4.9.7. The CA said it discovered the issue after reviewing prior Bugzilla incidents and checking its ARL/CRL endpoints, noting a 365 days and 1 second lapse between issuing date and NextUpdate date for the Root ARL and similar behavior for CRLs that should last 10 days. Izenpe stated it tested a configuration change in a development environment to subtract 1 second and then updated its configuration when reissuing the ARL. It reported that it published a new ARL and that publishing new CRLs for intermediate certificates was planned for 2021-10-29. A later comment confirmed that the CRLs were published without the extra second duration. Mozilla indicated it would close the bug on 16-Feb-2022 unless there were questions, and the bug is resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:13 UTC Revised: 2026-06-16 19:15 UTC Confidence: 0.86 3 comments
Chronology
  1. Izenpe identified that its ARL/CRL NextUpdate timing exceeded the intended validity duration by one second and began testing a configuration change.
  2. Izenpe published a new ARL and updated intermediate CRLs so they no longer included the extra one-second duration.
Thread Activity
  1. Izenpe S.A. — Izenpe explained that its Root ARL and CRLs had a one-second lapse beyond the configured validity period, citing BR 4.9.7, and described testing and planned reissuance steps.
  2. Izenpe S.A. — Izenpe stated that the CRLs are now published without the extra second duration.
  3. Mozilla representative — Mozilla said it would close the bug on 16-Feb-2022 unless there were questions or issues to discuss.
Participants
Izenpe S.A. Mozilla representative
Similar Local Cases
#1876565 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-01-25 · Closed 2024-04-06 · 98% similar
Izenpe: Not allowed Qualifier ID OID on Certificate Policies extension
#1921254 RESOLVED Certificate Misissuance Self Reported Incident Opened 2024-09-26 · Closed 2025-02-19 · 95% similar
Izenpe: Duplicate attribute in Subject
#1945867 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-02-04 · Closed 2025-04-18 · 94% similar
Izenpe: Incorrect Unicode characters in Subject
#1948600 RESOLVED Self Reported Incident Policy Document Issue Opened 2025-02-17 · Closed 2025-07-01 · 92% similar
IZENPE: Outdated CPS for Izenpe Root
#1976256 RESOLVED Self Reported Incident Opened 2025-07-08 · Closed 2025-11-20 · 86% similar
IZENPE: IssuingDistributionPoint extension in CRLs not marked as Critical
#1996857 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-10-28 · Closed 2025-12-11 · 79% similar
IZENPE: not allowed Key Usage in ocsp responder certificate
#1906028 RESOLVED Self Reported Incident Audit Finding Opened 2024-07-03 · Closed 2024-08-15 · 78% similar
Microsoft PKI Services: Vulnerability Management Exception Tracking
#1653284 RESOLVED Self Reported Incident Opened 2020-07-16 · Closed 2023-02-22 · 78% similar
Izenpe: incorrect value in stateOrProvinceName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action