← Krajowa Izba Rozliczeniowa S.A. (KIR) cases
Bugzilla #1921598 Certificate Misissuance

KIR: SZAFIR Trusted CA3 intermediate CA certificate policies extension non-compliance (Reserved Certificate Policy Identifiers missing)

RESOLVED FIXED Krajowa Izba Rozliczeniowa S.A. (KIR)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Krajowa Izba Rozliczeniowa S.A. (KIR) reported that an incident occurred where one intermediate certificate was incorrectly issued. Specifically, the Certificate Policies extension in the SZAFIR Trusted CA3 Intermediate CA was missing Reserved Certificate Policy Identifiers indicating adherence and compliance with the S/MIME BR. KIR said it was first notified by an email message from Rob Stradling posted to k**********t@kir.pl. KIR stated the impacted intermediate CA certificate had not yet been revoked at the time of the report and that it was developing a plan to safely switch issuance to a new intermediate CA certificate and retire or revoke the SZAFIR Trusted CA3 intermediate CA certificate, with a migration plan to be posted until Oct 11, 2025. In the thread, KIR described the root cause as an incorrect value in the Certiifcation Policy field in an updated CA generation procedure used during the Oct 11, 2023 generation ceremony. KIR reported remediation including updating CA generation procedures, adding a compliance check, reviewing certificate profiles, and implementing an automatic linter for intermediate CA certificate checks; KIR also stated the migration plan and revocation date of the impacted certificate had been executed. Mozilla requested a closure summary, and KIR provided one and requested closure; Mozilla indicated it would close the bug on 19-February-2025 unless remaining issues were discussed. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:15 UTC Revised: 2026-06-16 19:16 UTC Confidence: 0.90 8 comments
Chronology
  1. SZAFIR Trusted CA3 intermediate CA certificate was generated using an updated procedure containing an incorrect Certiifcation Policy field value.
  2. KIR was notified by email from Rob Stradling about the intermediate CA certificate issue.
  3. Intermediate CA certificate profile was updated to be compliant with S/MIME BR.
  4. Automatic linter for intermediate CA certificate checks was reported as completed.
  5. KIR submitted an incident report closure summary and requested closure.
  6. Mozilla closed the incident unless remaining issues were discussed.
Thread Activity
  1. Kir representative — Opened the incident report describing the incorrectly issued intermediate certificate and the missing Reserved Certificate Policy Identifiers in the Certificate Policies extension.
  2. Sectigo — Quoted S/MIME BR section 4.9.1.2 and warned that failing to revoke the Szafir Trusted CA3 intermediate certificate within seven days would cause another incident.
  3. Kir representative — Responded that KIR was aware of the seven-day revocation requirement but would file a new incident for delayed revocation at the right time due to the impact described.
  4. Kir representative — Reported that the action item to implement an automatic linter for intermediate CA certificate checks was completed.
  5. Kir representative — Stated that all action items had been completed and there were no further updates.
  6. Mozilla representative — Requested a Closure Summary template and asked KIR to attest that all action items were completed.
  7. Kir representative — Provided the closure summary, including incident description, root cause, remediation, and commitment summary, and requested closure.
  8. Mozilla representative — Indicated Mozilla would close the bug on 19-February-2025 unless remaining issues were discussed.
Participants
Kir representative Community commenter Sectigo Mozilla representative
Similar Local Cases
#1921597 RESOLVED Certificate Misissuance Opened 2024-09-28 · Closed 2025-02-19 · 100% similar
KIR: Intermediate CA - SZAFIR Trusted CA4 - Certificate Policies extension - non-compliance
#1708965 RESOLVED Certificate Misissuance Opened 2021-05-02 · Closed 2023-02-22 · 94% similar
KIR S.A.: Certificates issued greater than stated in CPS
#1883843 RESOLVED Certificate Misissuance Opened 2024-03-06 · Closed 2024-08-13 · 77% similar
Entrust: EV TLS Certificate cPSuri missing
#1653504 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-07-17 · Closed 2023-02-22 · 76% similar
Sectigo: Certificates with RSA keys where modulus is not divisible by 8
#1676367 RESOLVED Certificate Misissuance Opened 2020-11-10 · Closed 2023-02-22 · 76% similar
NetLock: Issuance of >398-day precertificates after 2020-09-01
#1705647 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-04-16 · Closed 2023-02-22 · 76% similar
KIR S.A.: Invalid organizationName
#1838667 RESOLVED Certificate Misissuance Opened 2023-06-15 · Closed 2023-07-05 · 75% similar
Let's Encrypt: Duplicate Serial Numbers
#1705187 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-04-14 · Closed 2023-02-22 · 75% similar
KIR S.A.: CN domain not in SAN

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action