← D-TRUST cases
Bugzilla #1756122 Certificate Problem Report

D-TRUST: Wrong key usage (Key Agreement)

RESOLVED FIXED D-TRUST
AI Summary

D-TRUST SSL CA 2 2020 issued a certificate with incorrect key usage, specifying 'keyAgreement' instead of 'keyEncipherment'. The error was detected shortly after issuance on February 17, 2022, leading to the revocation of the certificate the same day. D-TRUST has since halted the issuance of certificates of this type and implemented additional checks to prevent future occurrences. A thorough investigation revealed misconfiguration and limitations in their pre-linting checks as contributing factors.

Model: gpt-4o-mini Generated: 2026-06-13 21:22 UTC Confidence: 0.95
Chronology
  1. New product type added; first certificate issued with incorrect key usage.
  2. Certificate revoked after internal checks.
  3. Rollback of the new product type initiated.
  4. New internal work instruction introduced.
  5. Contributions to Z-Lint project confirmed to prevent future issues.
Participants
Enrico Entschew
Similar Local Cases
#1647468 RESOLVED Certificate Problem Report Opened 2020-06-22 · Closed 2023-02-22 · 65% similar
D-TRUST: Wrong key usage (Key Encipherment)
#1939809 RESOLVED Certificate Problem Report Opened 2025-01-03 · Closed 2025-03-21 · 61% similar
D-Trust: QCStatement with http link of PKI Disclosure Statements
#1924385 RESOLVED Certificate Problem Report Opened 2024-10-13 · Closed 2025-07-16 · 61% similar
D-Trust: Missed Revocation of TLS certificates affected by Bugzilla 1884714
#1610303 RESOLVED Certificate Problem Report Opened 2020-01-20 · Closed 2023-02-22 · 61% similar
D-TRUST: Issuance of non-conformant SSL certificate
#1691117 RESOLVED Certificate Problem Report Opened 2021-02-05 · Closed 2023-02-22 · 61% similar
D-TRUST: Certificate with RSA key where modulus is not divisible by 8
#2012511 RESOLVED Certificate Problem Report Opened 2026-01-26 · Closed 2026-04-19 · 60% similar
D-Trust: CRL HTTP Media Type
#2009149 RESOLVED Certificate Problem Report Opened 2026-01-08 · Closed 2026-04-19 · 60% similar
D-Trust: Expired certificate provided on the CA TLS test website for demonstration of valid certificates
#1509512 RESOLVED Certificate Problem Report Opened 2018-11-23 · Closed 2023-02-22 · 60% similar
D-TRUST: syntax error in one tls certificate

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action