← Krajowa Izba Rozliczeniowa S.A. (KIR) cases
Bugzilla #1921598 Certificate Problem Report

KIR: Intermediate CA - SZAFIR Trusted CA3 - Certificate Policies extension - non-compliance

RESOLVED FIXED Krajowa Izba Rozliczeniowa S.A. (KIR)
AI Summary

An incident was reported involving the incorrect issuance of an intermediate certificate by Krajowa Izba Rozliczeniowa S.A. (KIR). The Certificate Policies extension in the SZAFIR Trusted CA3 Intermediate CA was missing Reserved Certificate Policy Identifiers, leading to non-compliance with S/MIME BR. This affected nearly 10,000 end-user certificates, which are critical for infrastructure and cannot be easily replaced. KIR has since updated its procedures and implemented additional checks to prevent future occurrences.

Model: gpt-4o-mini Generated: 2026-06-13 21:15 UTC Confidence: 1.00
Chronology
  1. Incident reported by Rob Stradling.
  2. Preliminary investigation began.
  3. KIR acknowledged the need for delayed revocation.
  4. Closure summary submitted.
Participants
Piotr Grabowski Rob Stradling B. Wilson
Similar Local Cases
#1921597 RESOLVED Certificate Problem Report Opened 2024-09-28 · Closed 2025-02-19 · 88% similar
KIR: Intermediate CA - SZAFIR Trusted CA4 - Certificate Policies extension - non-compliance
#1921596 RESOLVED Certificate Problem Report Opened 2024-09-28 · Closed 2025-02-19 · 77% similar
KIR: Failure to disclose intermediate certificate within 7 days in ccadb
#1921591 RESOLVED Certificate Problem Report Opened 2024-09-28 · 69% similar
KIR: Failure to disclose intermediate certificate within 7 days in ccadb
#1922572 RESOLVED Certificate Problem Report Opened 2024-10-03 · Closed 2025-05-08 · 64% similar
KIR: Delayed revocation within seven (7) days for bug 1921598
#1705647 RESOLVED Certificate Problem Report Opened 2021-04-16 · Closed 2023-02-22 · 60% similar
KIR S.A.: Invalid organizationName
#1705832 RESOLVED Certificate Problem Report Opened 2021-04-16 · Closed 2023-02-22 · 60% similar
KIR S.A.: DV certificates with locality name, organization name and stateOrProvinceName
#1705187 RESOLVED Certificate Problem Report Opened 2021-04-14 · Closed 2023-02-22 · 59% similar
KIR S.A.: CN domain not in SAN
#1705337 RESOLVED Certificate Problem Report Opened 2021-04-15 · Closed 2023-02-22 · 57% similar
KIR S.A.: Invalid localityName + CRL Revoked but OCSP Unknown

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action