Certigna: TLS certificates with Basic constraint non-critical
Certigna reported a compliance issue involving TLS certificates issued without the Basic Constraint extension marked as critical. This issue was identified on March 4, 2024, after a third-party report highlighted the non-conformity, which affected 3,661 valid OVCP TLS certificates primarily used by French state ministries. Following the discovery, Certigna ceased issuance of TLS certificates until the profiles were corrected and the Certificate Policy/Certification Practice Statement was updated. All affected certificates were subsequently revoked by March 26, 2024. The CA has implemented corrective actions and is now compliant with the Baseline Requirements.
- Issuance of non-compliant TLS certificates began.
- Non-conformity reported and issuance of TLS certificates stopped.
- Revocation of all affected certificates completed.
- Dhimyotis representative — Initial report created detailing the non-compliance issue.
- Google representative — Provided feedback on the initial report and requested additional details.
- Dhimyotis representative — Submitted additional information regarding the incident.
- Dhimyotis representative — Confirmed that all actions have been implemented and requested closure of the ticket.