Izenpe: Not allowed Qualifier ID OID on Certificate Policies extension
Izenpe reported a compliance issue found during its own analysis of its certificates. The CA identified that it was including the OID "1.3.6.1.5.5.7.2.2" (unotice) in the certificatePolicies extension on its DV and OV profiles, even though the BR section cited in the report only accepts policyQualifier OID id-qt-cps (OID: 1.3.6.1.5.5.7.2.1) under that extension. Izenpe stated the affected certificates were issued since 15 Sept 2023, totaling 266 DV/OV certificates, and that it stopped issuing these certificates on 25 Jan 2024. The CA then updated its DV and OV SSL profiles to remove the disallowed OID and resumed issuing certificates; it reported the first reissued certificate on 26 Jan 2024. Izenpe also reported completing revocation of all affected certificates on 30 Jan 2024 and later installing and configuring zlint in production, stating no issues were detected on new certificates. Mozilla indicated it would close the incident unless questions remained, and the bug is resolved as FIXED.
- Izenpe’s DV and OV certificates began including the unotice policyQualifier OID in the certificatePolicies extension.
- Izenpe stopped issuing DV and OV certificates after identifying the disallowed policyQualifier OID in certificatePolicies.
- Izenpe resumed issuing DV and OV certificates after updating profiles to remove the disallowed OID.
- Izenpe completed revocation of all certificates affected by the issue.
- Izenpe installed and configured zlint in production and reported no issues detected on new certificates.
- Mozilla closed the incident on or about 5-Apr-2024 unless questions remained.
- Izenpe S.A. — Created an incident report stating Izenpe included OID 1.3.6.1.5.5.7.2.2 in the certificatePolicies extension for DV/OV, cited a BR violation, reported 266 affected certificates issued since 15-Sep-2023, and said it stopped issuing those certificates.
- Izenpe S.A. — Reported that Izenpe resumed issuing DV/OV certificates after changing profiles to remove OID 1.3.6.1.5.5.7.2.2 and provided a crt.sh link for the first reissued certificate.
- Izenpe S.A. — Reported completion of revocation for all affected certificates.
- Izenpe S.A. — Reported success installing and configuring zlint in production and stated no issues were detected once it analyzed new certificates.
- Mozilla representative — Indicated Mozilla would close the incident on or about Friday, 5-Apr-2024 unless there were questions.