← Certigna cases
Bugzilla #1963663 Incident Certificate Misissuance

Certigna: Multiple Reserved Certificate Policy Identifiers in CA certificates

RESOLVED FIXED Certigna
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Certigna reported an incident after the Chrome Root Program informed it of a violation of the TLS Baseline Requirements. The issue was that, in March 2024, Certigna generated new intermediate CA certificates that included multiple reserved certificate policy identifiers in the CA certificates’ Certificate Policies extension. Certigna stated that its teams misinterpreted the requirement in TLS Baseline Requirements v2.0.2, and that the “Ballot SC083v3” later corrected the requirement to require exactly one Reserved Certificate Policy Identifier. Certigna stopped issuing certificates under the impacted CAs pending conclusions, notified affected customers and relevant bodies, and then revoked the concerned CAs and the subscriber certificates on 05/05/2025. Certigna also reported that it integrated PKILint (via PKI Metal) into its verification process to detect errors related to multiple reserved OIDs. The incident report was later closed with a closure summary describing revocation and remediation actions, and Certigna requested closure.

Model: gpt-5.4-nano Generated: 2026-06-13 21:29 UTC Revised: 2026-06-16 18:23 UTC Confidence: 0.86 10 comments
Chronology
  1. Certigna generated new intermediate CA certificates that included multiple reserved certificate policy identifiers.
  2. Certigna identified the potential non-compliance after receiving notification from the Chrome Root Program.
  3. Certigna revoked the concerned CAs and the subscriber certificates.
  4. The CCADB incident report was scheduled to be closed (final call for comments).
Thread Activity
  1. Dhimyotis representative — Opened a preliminary incident report stating Chrome Root Program notified Certigna of a TLS Baseline Requirements violation involving multiple reserved certificate policy identifiers in intermediate CA certificates.
  2. Certigna — Explained Certigna’s interpretation at the time of issuance and stated it revoked the concerned CAs and subscriber certificates on 05/05/2025 while preparing a full incident report.
  3. Certigna — Posted the full incident report with timeline, impact, and root cause (misinterpretation of the first requirement) and described that issuance was stopped in response to the incident.
  4. Dhimyotis representative — Submitted a report closure summary describing remediation (revocation and awareness) and commitments (increased vigilance and control tools), requesting closure.
  5. Certigna — Responded that Certigna was not using PKILint when the CAs were generated and stated it later integrated PKILint into its verification process.
  6. CCADB representative — Issued a final call for comments and indicated the incident report would be closed on approximately 2025-06-12.
Participants
Dhimyotis representative Community commenter Certigna CCADB representative Mozilla representative
Similar Local Cases
#1883416 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2024-03-04 · Closed 2024-08-28 · 100% similar
Certigna: TLS certificates with Basic constraint non-critical
#1983955 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2025-08-19 · Closed 2025-09-15 · 97% similar
Certigna: Subscriber certificate with EKU clientAuth only
#2004732 RESOLVED Ca Certificate Compliance Incident Opened 2025-12-08 · Closed 2026-01-05 · 96% similar
Certigna: AIA CA issuer field pointing to PEM encoded cert
#2011314 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Externally Reported Incident Opened 2026-01-19 · Closed 2026-06-23 · 86% similar
Netlock: unspecifed revocation code (0) in CRL
#1951415 RESOLVED Certificate Misissuance Delayed Revocation Opened 2025-03-03 · Closed 2025-05-08 · 86% similar
Chunghwa Telecom: Failure to check restrictive CAA record during Migration
#1961406 RESOLVED Certificate Misissuance Opened 2025-04-18 · Closed 2025-07-02 · 85% similar
SSL.com: DCV bypass and issue fake certificates for any MX hostname
#1986968 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-09-04 · Closed 2026-04-06 · 85% similar
Financijska agencija (Fina): Mis-issued certificates
#1950574 RESOLVED Ca Certificate Compliance Incident Revocation Issue Opened 2025-02-26 · Closed 2025-09-15 · 85% similar
SECOM: S/MIME CA Modified Opinion Report of Cybertrust Japan (CTJ)

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action