← Certigna cases
Bugzilla #1900654 Revocation Issue

Certigna: ARL without reason code for recent revoked CA certificates

RESOLVED FIXED Certigna
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

In March 2024, CERTIGNA generated new intermediate CA certificates to enable automation of certificate issuance, then revoked and replaced them after deciding to change their certificate profiles. The revocation reason was not included in the ARL produced after the revocation, resulting in non-compliance with Mozilla Baseline Requirements for CRL/OCSP responses for subordinate CA certificates. CERTIGNA reported that there was no impact on end-entity certificates because no certificates were issued using these CA certificates. CERTIGNA investigated the issue, updated its “ARL generation procedure” and compliance management procedure, and generated and published new ARLs with reason codes for the affected records. A community member asked for additional reporting details and noted the incident report did not fully meet expectations, including an incomplete timeline and insufficient root-cause/remediation detail. CERTIGNA later stated that all action items were implemented and operational, and the ticket was set to be closed unless further issues were discussed. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:28 UTC Revised: 2026-06-16 18:22 UTC Confidence: 0.90 8 comments
Chronology
  1. CERTIGNA generated four intermediate CA certificates as part of automation for certificate issuance.
  2. CERTIGNA revoked and replaced the four intermediate CA certificates during a key ceremony.
  3. CERTIGNA received an alert that its ARL records were non-compliant with Mozilla Baseline Requirements.
  4. CERTIGNA reviewed ARL generation requirements and updated its ARL generation and compliance management procedures.
  5. CERTIGNA reported that all action items were implemented and operational.
Thread Activity
  1. Dhimyotis representative — Opened an incident report stating that CERTIGNA’s ARL lacked a revocation reason code for recently revoked intermediate CA certificates and described the impact, timeline, root cause, and action items.
  2. Community commenter — Requested clarification and additional details, including how many intermediates were created/revoked, whether full certificate details were provided, and a more complete timeline.
  3. Dhimyotis representative — Provided the crt.sh IDs and stated the four revoked intermediate CA certificates were generated on 2024-03-13 and revoked on 2024-03-26.
  4. Google representative — Commented that the report fell short of expectations, citing an incomplete timeline, formatting/template issues, and concerns about the sufficiency of the root cause and remediation.
  5. Dhimyotis representative — Supplied an expanded timeline and additional sections (what went well/what didn’t go well/where we got lucky) and added an extra action item to study a script for LAR profile compliance checks.
  6. Mozilla representative — Asked for an update to the action items in the bug.
  7. Dhimyotis representative — Reported that all actions were implemented and operational and that the ticket could be closed.
  8. Mozilla representative — Indicated the bug would be closed the next day unless issues remained to be discussed.
Participants
Dhimyotis representative Community commenter Google representative Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1890685 RESOLVED Revocation Issue Certificate Misissuance Opened 2024-04-09 · Closed 2025-02-21 · 85% similar
Entrust: Failure to revoke EV TLS certificates issued before CPS update
#1896596 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-05-14 · Closed 2024-07-24 · 82% similar
SECOM: Certificates Issued with lower case value in subject:countryName
#1910322 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-07-29 · Closed 2025-06-18 · 78% similar
DigiCert: Random value in CNAME without underscore prefix
#1650910 RESOLVED Self Reported Incident Audit Finding Revocation Issue Opened 2020-07-06 · Closed 2023-02-22 · 77% similar
DigiCert: Inconsistent EV audits
#1897346 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-05-17 · Closed 2024-07-24 · 77% similar
SECOM: Difference in upper and lower case between CN field and SAN
#1645686 RESOLVED Certificate Misissuance Revocation Issue Opened 2020-06-14 · Closed 2023-02-22 · 76% similar
Sectigo: Lack of input validation in stateOrProvinceName
#1924385 RESOLVED Ca Certificate Compliance Revocation Issue Closure Request Opened 2024-10-13 · Closed 2025-07-16 · 76% similar
D-Trust: Missed Revocation of TLS certificates affected by Bugzilla 1884714
#1894054 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-04-29 · Closed 2024-07-03 · 75% similar
SwissSign: MPKI step-up process sets wrong JoI Locality

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action