← Izenpe S.A. cases
Bugzilla #1922844
Certificate Problem Report
Izenpe: Not allowed Qualifier ID OID on Certificate Policies extension of Precertificates
RESOLVED
FIXED
Izenpe S.A.
AI Summary
Izenpe S.A. reported an issue regarding precertificates that included an incorrect Qualifier ID OID in the Certificate Policies extension. Initially, a set of certificates was revoked due to this misconfiguration, but it was later discovered that some precertificates had not been included in the revocation process. After identifying the oversight, all affected precertificates were revoked, and measures were implemented to ensure that such issues would be caught in the future. The incident did not impact clients as the certificates were never issued.
Chronology
- Bug 1876565 opened, listing affected certificates.
- Discovery of additional precertificates that were not revoked.
- Revocation of all identified precertificates.
- Task created to move precertificates to postlint server.
- Closure summary provided for the incident.
Participants
David Fernandez
Ryan Dickson
Ben Wilson
External References
Similar Local Cases
Izenpe: Not allowed Qualifier ID OID on Certificate Policies extension
IZENPE: not allowed Key Usage in ocsp responder certificate
Izenpe: Duplicate attribute in Subject
certSIGN: Missing certificate from the list of bad order subject attributtes
DigiCert: 4 CRLs unavailable or not responding
NETLOCK: SSL certificates with OU field
IZENPE: Failed to respond a Certificate Problem Report within 24 hours and create a preliminary report in 72 hours
Izenpe: CRL and ARL exceed validity period value by one second