← Certigna cases
Bugzilla #1774171 Certificate Misissuance

Certigna: Precertificate with a validity period greater than 398-days

RESOLVED DUPLICATE Certigna
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The case reports that Certigna issued a precertificate with a validity period greater than 398 days. The reporter identified the specific precertificate on crt.sh and noted that it exceeded the expected validity limit. Certigna responded that it launched internal investigations to determine the origin of the 400-day validity issuance, stating the issue appeared linked to a specific certificate renewal that had not been corrected by its automatic verification scripts. Certigna confirmed that only this certificate was affected, that revocation actions had been initiated, and that the incident had been communicated to CA and RA teams while awaiting investigation results and corrective actions. Certigna also stated it would create a detailed bug report within 24 hours and report the incident to its assessment and supervisory bodies. The bug was later marked as a duplicate of bug 1774418.

Model: gpt-5.4-nano Generated: 2026-06-13 21:26 UTC Revised: 2026-06-16 18:22 UTC Confidence: 0.86 7 comments
Chronology
  1. Certigna issued a precertificate with a validity period of about 400 days (greater than 398 days).
  2. Certigna created a new Bugzilla report (bug 1774418) to provide more details on the incident’s origin and corrective actions.
  3. This bug was marked as a duplicate of bug 1774418.
Thread Activity
  1. Lebihan representative — Reported finding a Certigna precertificate on crt.sh with a validity period greater than 398 days.
  2. Sectigo — Asked why the issue happened again, referencing a prior incident report where Certigna said certificates would not be issued with validity greater than 397 days.
  3. Dhimyotis representative — Said Certigna launched internal investigations, indicated the issuance seemed linked to a renewal not corrected by automatic verification scripts, and confirmed only one certificate was affected, revocation was initiated, and CA/RA teams were informed while awaiting corrective actions.
  4. Dhimyotis representative — Created bug 1774418 to report the incident with more details on origin and corrective actions.
  5. Mozilla representative — Marked this bug as a duplicate of bug 1774418.
Participants
Lebihan representative Sectigo Dhimyotis representative Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1883416 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2024-03-04 · Closed 2024-08-28 · 84% similar
Certigna: TLS certificates with Basic constraint non-critical
#1963663 RESOLVED Incident Certificate Misissuance Opened 2025-04-30 · Closed 2025-06-12 · 84% similar
Certigna: Multiple Reserved Certificate Policy Identifiers in CA certificates
#1838667 RESOLVED Certificate Misissuance Opened 2023-06-15 · Closed 2023-07-05 · 77% similar
Let's Encrypt: Duplicate Serial Numbers
#1676352 RESOLVED Certificate Misissuance Incident Opened 2020-11-10 · Closed 2023-02-22 · 77% similar
Microsec: Certificate validity period greater than 398 days
#1653504 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-07-17 · Closed 2023-02-22 · 76% similar
Sectigo: Certificates with RSA keys where modulus is not divisible by 8
#2023458 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-03-15 · Closed 2026-06-12 · 76% similar
D-Trust: TLS Precertificates Exceeding the Maximum Validity Period Allowed by the TLS Baseline Requirements
#1883843 RESOLVED Certificate Misissuance Opened 2024-03-06 · Closed 2024-08-13 · 75% similar
Entrust: EV TLS Certificate cPSuri missing
#1838371 RESOLVED Certificate Misissuance Opened 2023-06-14 · Closed 2024-01-19 · 75% similar
CFCA: certificate with an incorrect OrganizationName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action