← Disig, a.s. cases
Bugzilla #1888104
Certificate Problem Report
Disig: TLS certificate with basicConstraints not marked as critical
RESOLVED
FIXED
Disig, a.s.
AI Summary
Disig identified a compliance issue with a TLS certificate that had the basicConstraints extension not marked as critical, violating TLS BR 7.1.2.7.6. Following the notification, Disig revoked the affected certificate and issued a new one. They also discovered seven additional certificates with the same issue. To prevent future occurrences, Disig has implemented zlint into their CA system for pre-issuance checks. The issue has been resolved, and the corrective actions have been completed.
Chronology
- Disig notified about the non-compliance issue.
- Affected certificate revoked.
- zlint successfully implemented into production CA system.
Participants
Jozef Nigut
Peter Miskovic
Amir Aamidi
Rob Stradling
External References
Similar Local Cases
Disig: Two certificates with same serial number
Disig: Certificates with invalid embedded SCT signature
Disig: Certificates with incorrect Subject attribute order
Disig: Missing CA Disig R2I2 Certification Service Full CRL URLs in CCADB
Disig: Non-BR-Compliant OCSP Responders
Disig: Delayed Full Incident Report
Disig CRL broken, mis-listed? / CA list CRL links need auditing.
CFCA: Certificate with wrong crlDistributionPoints