← D-TRUST cases
Bugzilla #1939809 Ca Certificate Compliance Certificate Misissuance Closure Request

D-Trust: EV TLS/QWAC certificates used http QCStatement PDS links (ETSI EN 319 412-5 non-compliance)

RESOLVED FIXED D-TRUST
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

D-Trust disclosed an incident involving EV TLS certificates that are also Qualified Certificates for Website Authentication (QWAC). The certificates contained a QCStatement extension with an http link to the corresponding PKI Disclosure Statements (PDS), and D-Trust stated that ETSI EN 319 412-5 (QCS-4.3.4-03) only allows an https link for PDS. After D-Trust was made aware of the issue, it stopped production of this special EV certificate type and decided to revoke the affected certificates. D-Trust reported that 25 TLS certificates were affected and that they were revoked on 2025-01-03 18:30 UTC. D-Trust also adjusted dedicated certificate profiles and extended the use of PKI Lint to check ETSI requirements for the relevant certificate profiles. In the closure summary, D-Trust requested closure and stated that all action items disclosed in the incident report had been completed, and Mozilla indicated it would be queued to close on 19-Mar-2025. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:32 UTC Revised: 2026-06-16 10:00 UTC Confidence: 0.90 10 comments
Chronology
  1. D-Trust began investigating a reported potential ETSI EN 319 412-5 violation related to EV TLS/QWAC QCStatement PDS links.
  2. D-Trust halted production of the affected EV certificate type and decided to revoke the affected certificates within five days.
  3. D-Trust revoked all affected EV TLS/QWAC certificates (25 total) after adjusting certificate profiles.
  4. D-Trust reported that an additional measure was in place: PKI Lint checks for ETSI requirements for the relevant EV TLS/QWAC certificate profiles.
  5. D-Trust submitted an incident report closure summary describing remediation and completion of action items.
  6. Mozilla indicated the case would be queued to close.
Thread Activity
  1. Bdr representative — Opened a preliminary incident report stating that D-Trust issued EV TLS/QWAC certificates with QCStatement http links to PDS, which D-Trust said did not comply with ETSI EN 319 412-5, and that production was stopped and affected certificates would be revoked.
  2. Bdr representative — Submitted a final incident report stating that production was stopped, certificate profiles were adjusted, 25 affected certificates were revoked on 2025-01-03 18:30 UTC, and production restarted after adopting the certificate profile.
  3. Bdr representative — Posted a weekly update that there was nothing new to report and that D-Trust was on track.
  4. Bdr representative — Posted a weekly update that there was nothing new to report and that D-Trust was on track.
  5. Bdr representative — Reported that PKI Lint had been used to check ETSI requirements for the EV TLS certificates that are also QWACs since 31-01-2025.
  6. Bdr representative — Asked whether the incident could be closed.
  7. Mozilla representative — Requested a Closure Summary.
  8. Mozilla representative — Provided guidance on what the Closure Summary should include and requested attestation that action items were completed.
  9. D-Trust — Submitted the incident report closure summary, stating the incident description, root cause(s), remediation (revocation, profile modifications, PKI Lint extension), and that all action items were completed and closure was requested.
  10. Mozilla representative — Stated it would be queued to close on Wed., 19-Mar-2025.
Participants
Bdr representative Mozilla representative D-Trust
Similar Local Cases
#1682270 RESOLVED Ca Certificate Compliance Incident Closure Request Opened 2020-12-14 · Closed 2026-06-12 · 100% similar
D-TRUST: Private Key Disclosed by Customer as Part of CSR
#1691117 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2021-02-05 · Closed 2023-02-22 · 100% similar
D-TRUST: Certificate with RSA key where modulus is not divisible by 8
#1924385 RESOLVED Ca Certificate Compliance Revocation Issue Closure Request Opened 2024-10-13 · Closed 2025-07-16 · 100% similar
D-Trust: Missed Revocation of TLS certificates affected by Bugzilla 1884714
#1610303 RESOLVED Ca Certificate Compliance Opened 2020-01-20 · Closed 2023-02-22 · 95% similar
D-TRUST: Issuance of non-conformant SSL certificate
#1647468 RESOLVED Ca Certificate Compliance Opened 2020-06-22 · Closed 2023-02-22 · 95% similar
D-TRUST: Wrong key usage (Key Encipherment)
#1756122 RESOLVED Self Reported Incident Certificate Misissuance Opened 2022-02-18 · Closed 2023-02-22 · 95% similar
D-TRUST: Wrong key usage (Key Agreement)
#1793440 RESOLVED Self Reported Incident Certificate Misissuance Opened 2022-10-03 · Closed 2023-02-22 · 95% similar
D-TRUST: CRL not DER-encoded
#1896190 RESOLVED Ca Certificate Compliance Opened 2024-05-10 · Closed 2024-11-06 · 95% similar
D-Trust: Issuance of an EV certificate containing a mixup of the Subject's postalCode and localityName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action