← Certigna cases
Bugzilla #1883416
Certificate Misissuance
Certigna: TLS certificates with Basic constraint non-critical
RESOLVED
FIXED
Certigna
AI Summary
Certigna has been issuing TLS certificates since September 15, 2023, without the Basic Constraint extension marked as critical, which is a requirement under the Baseline Requirements. This issue was not identified by the monitoring team or automated tools, leading to the issuance of 3,661 non-compliant certificates, primarily used by French state ministries. Upon discovery, Certigna halted the issuance of TLS certificates and subsequently revoked all affected certificates. The incident has been resolved with corrective actions implemented.
Chronology
- Issuance of non-compliant certificates
- Incident reported and certificate issuance stopped
- Notification sent to subscribers regarding revocation
- Revocation of all affected certificates
- All actions implemented and ticket ready for closure
Participants
Josselin Allemandou
Ryan Dickson
Arnaud F.
Amir A.
Rob
R. Delval
Ben Wilson
External References
Similar Local Cases
Dhimyotis / Certigna: Certificates issued with validity periods greater than 398-days
Certigna: certificates issued with 2 SCT
e-commerce monitoring gmbh: certificate issued with two pre-certificates
Certigna: Issuance without respecting CAA records
Entrust: EV TLS Certificate cPSuri missing
Digicert: Failure to include CPS URI in 1 certificate
Dhimyotis / Certigna: Certificates issued with validity periods greater than 398-days
ACCV: Certificates issued with cRLIssuer in CDP extension