Certigna: Multiple Reserved Certificate Policy Identifiers in CA certificates
Certigna reported an incident after the Chrome Root Program informed it of a violation of the TLS Baseline Requirements. The issue was that, in March 2024, Certigna generated new intermediate CA certificates that included multiple reserved certificate policy identifiers in the CA certificates’ Certificate Policies extension. Certigna stated that its teams misinterpreted the requirement in TLS Baseline Requirements v2.0.2, and that the “Ballot SC083v3” later corrected the requirement to require exactly one Reserved Certificate Policy Identifier. Certigna stopped issuing certificates under the impacted CAs pending conclusions, notified affected customers and relevant bodies, and then revoked the concerned CAs and the subscriber certificates on 05/05/2025. Certigna also reported that it integrated PKILint (via PKI Metal) into its verification process to detect errors related to multiple reserved OIDs. The incident report was later closed with a closure summary describing revocation and remediation actions, and Certigna requested closure.
- Certigna generated new intermediate CA certificates that included multiple reserved certificate policy identifiers.
- Certigna identified the potential non-compliance after receiving notification from the Chrome Root Program.
- Certigna revoked the concerned CAs and the subscriber certificates.
- The CCADB incident report was scheduled to be closed (final call for comments).
- Dhimyotis representative — Opened a preliminary incident report stating Chrome Root Program notified Certigna of a TLS Baseline Requirements violation involving multiple reserved certificate policy identifiers in intermediate CA certificates.
- Certigna — Explained Certigna’s interpretation at the time of issuance and stated it revoked the concerned CAs and subscriber certificates on 05/05/2025 while preparing a full incident report.
- Certigna — Posted the full incident report with timeline, impact, and root cause (misinterpretation of the first requirement) and described that issuance was stopped in response to the incident.
- Dhimyotis representative — Submitted a report closure summary describing remediation (revocation and awareness) and commitments (increased vigilance and control tools), requesting closure.
- Certigna — Responded that Certigna was not using PKILint when the CAs were generated and stated it later integrated PKILint into its verification process.
- CCADB representative — Issued a final call for comments and indicated the incident report would be closed on approximately 2025-06-12.