← Apple Inc. cases
Bugzilla #1777757
Certificate Misissuance
Apple: EV TLS pre-certificates issued without EKU extension
RESOLVED
FIXED
Apple Inc.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
On July 1, 2022, Apple Public CA issued two EV TLS pre-certificates lacking the Extended Key Usage (EKU) extension, violating Baseline Requirements Section 7.1.2.3. The CA discovered the issue through an internal alert when the issuance of final certificates failed. Both pre-certificates were subsequently revoked, and a full report was promised by July 15, 2022. Apple implemented a remediation plan, which included using a workaround and upgrading their production environment. The issue was resolved by November 18, 2022, with no further remediation items pending.
Chronology
- Apple Public CA issued two EV TLS pre-certificates without EKU extension.
- Apple Public CA upgraded their production environment to resolve the issue.
Thread Activity
- Apple representative — Apple Public CA issued two EV TLS pre-certificates without an EKU extension.
- Apple representative — A full report will be provided no later than July 15, 2022.
- Apple representative — The unrelated performance fix has been addressed and we have upgraded our production environment.
Participants
Apple representative
Mozilla representative
External References
Similar Local Cases
Apple: TLS certificates issued outside the TTL of the CAA record
Entrust: S/MIME mailbox address not in subjectAltName
Asseco DS / Certum: TLS EV certificates with incorrect Subject attribute order
NAVER Cloud Trust Services: Incorrect keyUsage for ECC certificate
ACCV: Certificates issued with cRLIssuer in CDP extension
Hongkong Post: Invalid EV cert businessCategory
Entrust: SSL Certificates issued with Un-verified IP Addresses
e-commerce monitoring GmbH: CN domain not in SAN