← Certigna cases
Bugzilla #1983955 Ca Certificate Compliance Certificate Misissuance

Certigna: Subscriber certificate with EKU clientAuth only

RESOLVED FIXED Certigna
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Certigna disclosed an incident involving the issuance of client authentication certificates that only included the EKU clientAuth without the required serverAuth EKU or CA/Browser Forum reserved policy identifier. This issue was raised by Sectigo, prompting Certigna to halt the issuance of such certificates immediately on August 19, 2025. A total of 3,438 certificates were identified as affected, with 681 revoked through a mass revocation script. Certigna has committed to transitioning to a new dedicated CA for client authentication certificates and has completed all action items related to this incident. The incident has been resolved with all affected certificates revoked.

Model: gpt-4o-mini Generated: 2026-06-13 21:32 UTC Revised: 2026-06-16 18:23 UTC Confidence: 0.90 12 comments
Chronology
  1. Issuance of clientAuth certificates halted following compliance concerns raised by Sectigo.
  2. All affected clientAuth certificates were revoked.
Thread Activity
  1. Certigna — Opened a Preliminary Incident Report regarding clientAuth-only certificates.
  2. Google representative — Raised concerns about policy chaining and compliance with TLS BRs.
  3. Certigna — Provided details on the historical authority's OIDs and confirmed the suspension of clientAuth issuance.
  4. Certigna — Summarized the incident closure, detailing root causes and remediation actions.
  5. CCADB representative — Final call for comments on the Incident Report before closure.
Participants
Certigna Google representative CCADB representative
External References
Similar Local Cases
#1883416 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2024-03-04 · Closed 2024-08-28 · 99% similar
Certigna: TLS certificates with Basic constraint non-critical
#2004732 RESOLVED Ca Certificate Compliance Incident Opened 2025-12-08 · Closed 2026-01-05 · 98% similar
Certigna: AIA CA issuer field pointing to PEM encoded cert
#1963663 RESOLVED Incident Certificate Misissuance Opened 2025-04-30 · Closed 2025-06-12 · 97% similar
Certigna: Multiple Reserved Certificate Policy Identifiers in CA certificates
#1774418 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-06-15 · Closed 2023-04-19 · 89% similar
Certigna: Certificate issued with validity period greater than 398-days
#1963456 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-04-29 · Closed 2025-07-25 · 88% similar
GoDaddy: CA Certificates with HTTPS URL in AIA Field
#1981680 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Linting Quality Issue Opened 2025-08-07 · Closed 2025-09-26 · 86% similar
TunTrust: SSL OV mis-issuance against CP/CPS (Email attribute)
#1969296 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-05-29 · Closed 2025-07-22 · 80% similar
GoDaddy: Certificates with invalid embedded SCT signatures
#2031281 RESOLVED Ca Certificate Compliance Self Reported Incident Incident Certificate Misissuance Opened 2026-04-13 · Closed 2026-06-16 · 79% similar
CFCA: OCSP Responder Certificate Profile Deviations and OCSP Service Issues

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action