← Trustis cases
Bugzilla #1017562
Certificate Misissuance
Trustis: Certificate not version 3
RESOLVED
Trustis
AI Summary
A version 1 certificate was issued by Trustis, which does not comply with policy requirements for TLS end-entity certificates. The issue arose due to a technical problem related to browser updates that caused a malformed request during certificate issuance. Trustis has since revoked the problematic certificate and implemented additional checks to prevent future occurrences. A root cause analysis is ongoing to ensure compliance across all issued certificates.
Chronology
- Initial report of version 1 certificate issued.
- Trustis confirmed the certificate was issued due to a technical issue.
- Root cause identified as a browser compatibility issue.
- Trustis confirmed additional version 1 certificates were found.
Participants
Kurt Roeckx
Rob Horne
Kathleen Wilson
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
Trustis: SHA-1 serverAuth cert issued in November 2016
DigiCert: Verizon mis-issued test certificates
SHA-1 issuance by DocuSign root
DigiCert: DigiCert issued cert with CN too long
SHA-1 issuance by Visa root
DigiCert / Justica: Invalid DNS names
DigiCert / Terena: Metadata in OU fields
DigiCert / Siemens: Insufficient Serial Number Entropy