D-TRUST: Wrong key usage (Key Agreement)
D-TRUST identified a compliance issue where a certificate was incorrectly issued with the key usage 'keyAgreement' instead of 'keyEncipherment'. This misissuance occurred on February 17, 2022, shortly after a new product type was introduced. Upon detection by the quality assurance team, D-TRUST promptly revoked the affected certificate and halted further issuance of this product type. The CA has since implemented additional checks and rolled back the product to prevent future occurrences. The issue has been resolved, and the CA has contributed to the Z-Lint project to enhance detection of similar errors.
- D-TRUST issued a certificate with incorrect key usage.
- D-TRUST revoked the incorrectly issued certificate.
- D-TRUST rolled back the new product type.
- D-TRUST contributed changes to the Z-Lint project.
- Bdr representative — D-TRUST reported the incident and outlined the timeline of events.
- Bdr representative — D-TRUST provided an update on the incident report and actions taken.
- Bdr representative — D-TRUST updated on the implementation of additional checks.
- Bdr representative — D-TRUST confirmed the completion of measures and requested closure of the bug.
- Mozilla representative — Mozilla indicated the bug would be closed shortly.