← A-Trust cases
Bugzilla #1972887
Certificate Problem Report
A-Trust: TLS non-compliance detected during linter implementation
RESOLVED
A-Trust
AI Summary
A-Trust identified non-compliance issues with TLS certificates during the implementation of a linting mechanism. The issues included missing critical extensions and invalid subject orders. A total of 66 certificates were affected, with 20 remaining valid at the time of reporting. All non-compliant certificates were revoked within five days, and a commitment was made to implement mandatory linting for all TLS certificates moving forward.
Chronology
- Non-compliance identified
- Report of non-compliance submitted
- All non-compliant certificates revoked
Participants
Ramin Sabet
External References
Similar Local Cases
DigiCert: Non-BR Compliant Certificates - missing CP/CPS OID
DigiCert: TI Trust Technologies Global CA issued certificate with no subject alternative name extension
DigiCert / Thawte: CAA Mis-Issuance on mix of wildcard and non-wildcard DNS names in SAN
DigiCert: Insufficient entropy in serial numbers
DigiCert / CTJ: Metadata in OU fields, Reserved IP Address
DigiCert: Certificate Issues Identified on the Mailing List
DigiCert: Symantec non-constrained/non-disclosed intermediate CA certificates
Add DigiCert non-TLS Intermediate Certs to OneCRL