← Certigna cases
Bugzilla #1883416 Ca Certificate Compliance Certificate Misissuance

Certigna: TLS certificates with Basic constraint non-critical

RESOLVED FIXED Certigna
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Certigna reported a compliance issue involving TLS certificates issued without the Basic Constraint extension marked as critical. This issue was identified on March 4, 2024, after a third-party report highlighted the non-conformity, which affected 3,661 valid OVCP TLS certificates primarily used by French state ministries. Following the discovery, Certigna ceased issuance of TLS certificates until the profiles were corrected and the Certificate Policy/Certification Practice Statement was updated. All affected certificates were subsequently revoked by March 26, 2024. The CA has implemented corrective actions and is now compliant with the Baseline Requirements.

Model: gpt-4o-mini Generated: 2026-06-13 21:27 UTC Revised: 2026-06-16 18:22 UTC Confidence: 0.85 11 comments
Chronology
  1. Issuance of non-compliant TLS certificates began.
  2. Non-conformity reported and issuance of TLS certificates stopped.
  3. Revocation of all affected certificates completed.
Thread Activity
  1. Dhimyotis representative — Initial report created detailing the non-compliance issue.
  2. Google representative — Provided feedback on the initial report and requested additional details.
  3. Dhimyotis representative — Submitted additional information regarding the incident.
  4. Dhimyotis representative — Confirmed that all actions have been implemented and requested closure of the ticket.
Participants
Dhimyotis representative Google representative Community commenter Sectigo Certigna Mozilla representative
External References
Similar Local Cases
#1963663 RESOLVED Incident Certificate Misissuance Opened 2025-04-30 · Closed 2025-06-12 · 100% similar
Certigna: Multiple Reserved Certificate Policy Identifiers in CA certificates
#1983955 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2025-08-19 · Closed 2025-09-15 · 99% similar
Certigna: Subscriber certificate with EKU clientAuth only
#1887096 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2024-03-22 · Closed 2024-09-06 · 96% similar
Chunghwa Telecom: Wrong Extended Key Usage setting by GTLSCA
#1774418 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-06-15 · Closed 2023-04-19 · 90% similar
Certigna: Certificate issued with validity period greater than 398-days
#2004732 RESOLVED Ca Certificate Compliance Incident Opened 2025-12-08 · Closed 2026-01-05 · 89% similar
Certigna: AIA CA issuer field pointing to PEM encoded cert
#1887753 RESOLVED Certificate Misissuance Audit Finding Opened 2024-03-25 · Closed 2024-07-12 · 86% similar
Entrust: Delay in Updating CPS
#1888714 RESOLVED Certificate Misissuance Opened 2024-03-29 · Closed 2024-07-11 · 86% similar
Entrust: EV Certificate missing Issuer’s EV Policy OID
#1736064 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-10-15 · Closed 2023-02-22 · 85% similar
Sectigo: Subject field with unvalidated information included in certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action