← Disig, a.s. cases
Bugzilla #1888104
Certificate Misissuance
Disig: TLS certificate with basicConstraints not marked as critical
RESOLVED
FIXED
Disig, a.s.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
Disig, a.s. was notified about a TLS certificate and a corresponding precertificate that did not have the basicConstraints extension marked as critical, violating TLS BR 7.1.2.7.6. Following this discovery, Disig revoked the affected certificate on March 29, 2024, and issued a new compliant certificate. An incident report was prepared detailing the timeline and impact of the issue, which included identifying additional affected certificates. Disig has since implemented zlint into their production system to prevent future occurrences of similar compliance issues. The case is now considered resolved.
Chronology
- Disig notified about non-compliance with basicConstraints extension in TLS certificate.
- Affected certificate revoked and new compliant certificate issued.
- Disig implemented zlint into their production CA system.
Thread Activity
- Disig, a.s. — Disig has been notified about a leaf certificate with basicConstraints extension that is not marked as critical.
- Disig, a.s. — Certificate was revoked on March 29, 2024, and a new certificate has been issued.
- Disig, a.s. — Incident report issued detailing the non-compliance and corrective actions taken.
- Disig, a.s. — Successfully implemented zlint into the production CA system.
- Disig, a.s. — Disig considers the subject of this bug to be resolved.
Participants
Disig, a.s.
Mozilla representative
Community commenter
External References
Similar Local Cases
Disig: Certificates with incorrect Subject attribute order
Disig: Certificates with invalid embedded SCT signature
Disig: Two certificates with same serial number
Disig: Non-BR-Compliant Certificate Issuance
Certigna: TLS certificates with Basic constraint non-critical
IdenTrust: unintended creation of a Root CA certificate
SwissSign: MPKI step-up process sets wrong JoI Locality
Asseco DS / Certum: TLS EV certificates with incorrect Subject attribute order