← Certigna cases
Bugzilla #1963663
Certificate Problem Report
Certigna: Multiple Reserved Certificate Policy Identifiers in CA certificates
RESOLVED
FIXED
Certigna
AI Summary
Certigna faced an incident involving the issuance of CA certificates that included multiple reserved certificate policy identifiers, violating the TLS Baseline Requirements. The issue was identified by the Chrome Root Program, leading to the revocation of seven CA certificates and 286 impacted server certificates. The root cause was a misinterpretation of the requirements, which have since been clarified. Certigna has since implemented corrective measures, including the use of PKILint for future certificate validations.
Chronology
- Non-compliance start date
- Non-compliance identified
- Non-compliance ended with revocation
Participants
Josselin Allemandou
r.delval@certigna.com
rowleylaw@gmail.com
bwilson@mozilla.com
incident-reporting@ccadb.org
External References
Similar Local Cases
Certigna: Subscriber certificate with EKU clientAuth only
Apple: Public Key Reuse
Certigna: Revocation delay for TLS certificates with basic constraint not marked as critical
Certigna: ARL without reasoncode for recent revoked CA certificates
Certigna: Certificate issued with validity period greater than 398-days
Certigna: CRL URL Disclosure
Dhimyotis / Certigna: Failure to revoke in the timeline specified by the BRs
Certigna: AIA CA issuer field pointing to PEM encoded cert