← NAVER Cloud Trust Services cases
Bugzilla #1908130 Self Reported Incident Certificate Misissuance

NAVER Cloud Trust Services: Incorrect keyUsage for ECC certificate

RESOLVED FIXED NAVER Cloud Trust Services
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

NAVER Cloud Trust Services reported that it issued three ECDSA certificates for test websites that incorrectly included keyEncipherment in the keyUsage extension. The CA stated this violated Mozilla Baseline Requirements (BR) section "7.1.2.7.11 Subscriber Certificate Key Usage". NAVER Cloud Trust Services said it discovered the issue and, within 30 minutes, promptly revoked all three affected certificates and suspended certificate issuance pending further investigation. In its incident report, the CA identified the root cause as a manual certificate profile creation process combined with missing pre-lint lint sources (RFC 5480 and RFC 8813) from the pre-lint scope, which allowed the incorrect certificates to pass pre-lint. The CA reported actions including adding the missing ECDSA lint source(s) to the pre-lint system, investigating additional cases that pass lint checks, and improving the certificate issuance system to reduce manual settings and enforce BR-compliant keyUsage values. The CA later stated that analysis and actions were completed, and Mozilla indicated it would close the bug on 28-Aug-2024. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 20:55 UTC Revised: 2026-06-16 18:39 UTC Confidence: 0.90 6 comments
Chronology
  1. NAVER Cloud Trust Services issued three ECDSA certificates with incorrect keyUsage for test websites and then revoked them within about 30 minutes after discovery.
  2. NAVER Cloud Trust Services published a full incident report and detailed root cause and action items.
  3. NAVER Cloud Trust Services stated analysis and actions were completed; Mozilla planned closure.
Thread Activity
  1. Navercorp representative — Posted a preliminary incident report describing three ECDSA certificates with keyEncipherment in keyUsage, the BR violation, and that the certificates were revoked within 30 minutes after awareness.
  2. Navercorp representative — Provided an incident report with impact, timeline, root cause (manual profile creation and missing RFC 5480/RFC 8813 lint sources), and action items including adding lint sources and improving issuance controls.
  3. Navercorp representative — Updated action item statuses, including completion of adding ECDSA lint source to the pre-lint system and setting requirements for test-environment generation and external lint validation before production.
  4. Navercorp representative — Refreshed action item statuses, marking the listed mitigations and process changes as completed.
  5. Navercorp representative — On behalf of NAVER Cloud Trust Services, stated that analysis and actions were completed and there was no new information since a prior comment.
  6. Mozilla representative — Indicated Mozilla would look at closing the bug on 28-Aug-2024.
Participants
Navercorp representative Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1908128 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-07-16 · Closed 2024-08-28 · 100% similar
NAVER Cloud Trust Services: Certificate issued with incorrect OCSP URI in AIA
#1866448 RESOLVED Certificate Misissuance Incident Opened 2023-11-24 · Closed 2024-02-14 · 97% similar
NAVER Cloud Trust Services: DV Certificate issued with improperly validated
#1843268 RESOLVED Self Reported Incident Opened 2023-07-13 · Closed 2024-05-09 · 91% similar
NAVER Cloud Trust Services: OV certificate issued with OU field
#1845269 RESOLVED Certificate Misissuance Incident Opened 2023-07-25 · Closed 2023-09-29 · 91% similar
NAVER Cloud Trust Services: commonName not in SAN
#1772411 RESOLVED Self Reported Incident Opened 2022-06-02 · Closed 2024-05-09 · 88% similar
NAVER Cloud Trust Services: Failure to Respond to May 2022 Survey
#1752670 RESOLVED Certificate Misissuance Self Reported Incident Opened 2022-01-29 · Closed 2024-05-09 · 81% similar
Let's Encrypt: TLS Using ALPN Allows Additional Identifiers in Challenge Certificate
#1910195 RESOLVED Certificate Misissuance Self Reported Incident Opened 2024-07-26 · Closed 2024-09-06 · 81% similar
IdenTrust: Invalid special characters in S/MIME Certificates
#1876565 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-01-25 · Closed 2024-04-06 · 81% similar
Izenpe: Not allowed Qualifier ID OID on Certificate Policies extension

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action