← Izenpe S.A. cases
Bugzilla #1876565 Self Reported Incident Certificate Misissuance

Izenpe: Not allowed Qualifier ID OID on Certificate Policies extension

RESOLVED FIXED Izenpe S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Izenpe reported a compliance issue found during its own analysis of its certificates. The CA identified that it was including the OID "1.3.6.1.5.5.7.2.2" (unotice) in the certificatePolicies extension on its DV and OV profiles, even though the BR section cited in the report only accepts policyQualifier OID id-qt-cps (OID: 1.3.6.1.5.5.7.2.1) under that extension. Izenpe stated the affected certificates were issued since 15 Sept 2023, totaling 266 DV/OV certificates, and that it stopped issuing these certificates on 25 Jan 2024. The CA then updated its DV and OV SSL profiles to remove the disallowed OID and resumed issuing certificates; it reported the first reissued certificate on 26 Jan 2024. Izenpe also reported completing revocation of all affected certificates on 30 Jan 2024 and later installing and configuring zlint in production, stating no issues were detected on new certificates. Mozilla indicated it would close the incident unless questions remained, and the bug is resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:13 UTC Revised: 2026-06-16 19:15 UTC Confidence: 0.90 5 comments
Chronology
  1. Izenpe’s DV and OV certificates began including the unotice policyQualifier OID in the certificatePolicies extension.
  2. Izenpe stopped issuing DV and OV certificates after identifying the disallowed policyQualifier OID in certificatePolicies.
  3. Izenpe resumed issuing DV and OV certificates after updating profiles to remove the disallowed OID.
  4. Izenpe completed revocation of all certificates affected by the issue.
  5. Izenpe installed and configured zlint in production and reported no issues detected on new certificates.
  6. Mozilla closed the incident on or about 5-Apr-2024 unless questions remained.
Thread Activity
  1. Izenpe S.A. — Created an incident report stating Izenpe included OID 1.3.6.1.5.5.7.2.2 in the certificatePolicies extension for DV/OV, cited a BR violation, reported 266 affected certificates issued since 15-Sep-2023, and said it stopped issuing those certificates.
  2. Izenpe S.A. — Reported that Izenpe resumed issuing DV/OV certificates after changing profiles to remove OID 1.3.6.1.5.5.7.2.2 and provided a crt.sh link for the first reissued certificate.
  3. Izenpe S.A. — Reported completion of revocation for all affected certificates.
  4. Izenpe S.A. — Reported success installing and configuring zlint in production and stated no issues were detected once it analyzed new certificates.
  5. Mozilla representative — Indicated Mozilla would close the incident on or about Friday, 5-Apr-2024 unless there were questions.
Participants
Izenpe S.A. Mozilla representative
External References
Similar Local Cases
#1921254 RESOLVED Certificate Misissuance Self Reported Incident Opened 2024-09-26 · Closed 2025-02-19 · 100% similar
Izenpe: Duplicate attribute in Subject
#1945867 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-02-04 · Closed 2025-04-18 · 100% similar
Izenpe: Incorrect Unicode characters in Subject
#1738421 RESOLVED Self Reported Incident Audit Finding Opened 2021-10-29 · Closed 2023-02-22 · 98% similar
Izenpe: CRL and ARL exceed validity period value by one second
#1948600 RESOLVED Self Reported Incident Policy Document Issue Opened 2025-02-17 · Closed 2025-07-01 · 94% similar
IZENPE: Outdated CPS for Izenpe Root
#1559765 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-06-17 · Closed 2023-02-22 · 92% similar
Izenpe: Multiple invalid EV certificates issued
#1996857 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-10-28 · Closed 2025-12-11 · 91% similar
IZENPE: not allowed Key Usage in ocsp responder certificate
#1651026 RESOLVED Certificate Misissuance Incident Remediation Tracking Opened 2020-07-07 · Closed 2023-02-22 · 89% similar
Izenpe: certificate issued to internal domain
#1976256 RESOLVED Self Reported Incident Opened 2025-07-08 · Closed 2025-11-20 · 87% similar
IZENPE: IssuingDistributionPoint extension in CRLs not marked as Critical

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action