← Krajowa Izba Rozliczeniowa S.A. (KIR) cases
Bugzilla #1921597
Certificate Problem Report
KIR: Intermediate CA - SZAFIR Trusted CA4 - Certificate Policies extension - non-compliance
RESOLVED
FIXED
Krajowa Izba Rozliczeniowa S.A. (KIR)
AI Summary
An incident was reported involving the incorrect issuance of two intermediate CA certificates by Krajowa Izba Rozliczeniowa S.A. (KIR). The Certificate Policies extensions in the SZAFIR Trusted CA4 Intermediate CA certificate were missing Reserved Certificate Policy Identifiers, which are necessary for compliance with TLS BR. The issue was identified on September 25, 2024, following an email from Rob Stradling. Remediation steps included updating procedures, implementing additional checks, and revoking the affected certificates.
Chronology
- Incident reported by Rob Stradling.
- Affected certificate revoked.
- Incident report closure summary submitted.
Participants
Piotr Grabowski
Rob Stradling
B. Wilson
External References
Similar Local Cases
KIR: Intermediate CA - SZAFIR Trusted CA3 - Certificate Policies extension - non-compliance
KIR: Failure to disclose intermediate certificate within 7 days in ccadb
KIR: Failure to disclose intermediate certificate within 7 days in ccadb
KIR: Delayed revocation within seven (7) days for bug 1921598
KIR S.A.: DV certificates with locality name, organization name and stateOrProvinceName
KIR S.A.: CN domain not in SAN
KIR S.A.: Invalid localityName + CRL Revoked but OCSP Unknown
KIR S.A.: Invalid organizationName