← Certigna cases
Bugzilla #1886442
Certificate Problem Report
Certigna: Revocation delay for TLS certificates with basic constraint not marked as critical
RESOLVED
FIXED
Certigna
AI Summary
Certigna faced a delay in revoking TLS certificates that were issued without the Basic Constraint extension marked as critical, violating Baseline Requirements. The issue was identified on March 4, 2024, but not all affected certificates were revoked within the required five-day period. The incident impacted certificates issued between September 15, 2023, and March 4, 2024, primarily affecting French state ministries. Although Certigna halted certificate issuance and updated their processes, the revocation of all affected certificates was completed by April 9, 2024.
Chronology
- Issuance of non-conform certificates
- Non-conformity reported to Certigna
- Mail sent to subscribers about revocation
- Revocation of all affected certificates
- Final certificate revoked for health organization
Participants
Josselin Allemandou
Wayne R.
R. Delval
B. Wilson
External References
Similar Local Cases
Certigna: Multiple Reserved Certificate Policy Identifiers in CA certificates
Certigna: ARL without reasoncode for recent revoked CA certificates
Dhimyotis / Certigna: Intermediate CAs missing audits
Certigna: Certificate issued with validity period greater than 398-days
Certigna: CRL URL Disclosure
Certigna: AIA CA issuer field pointing to PEM encoded cert
Certigna: Failure to respond to CPR within 24 hours
Certigna: Subscriber certificate with EKU clientAuth only