← Certigna cases
Bugzilla #1983955 Certificate Problem Report

Certigna: Subscriber certificate with EKU clientAuth only

RESOLVED FIXED Certigna
AI Summary

Certigna Services CA issued client authentication certificates that only included the clientAuth Extended Key Usage (EKU) without the required serverAuth EKU or CA/Browser Forum reserved policy identifier. This raised compliance concerns with the TLS Baseline Requirements. Following a notification from Sectigo, Certigna suspended the issuance of these certificates and initiated a mass revocation of affected certificates. All impacted subscribers were contacted, and the transition to a new dedicated client authentication CA was expedited. The incident has been resolved with all corrective actions completed.

Model: gpt-4o-mini Generated: 2026-06-13 21:32 UTC Confidence: 0.95
Chronology
  1. Incident identified and certificate issuance suspended.
  2. Mass revocation of affected certificates executed.
  3. Incident closure summary provided.
Participants
r.delval@certigna.com chrome-root-program@google.com incident-reporting@ccadb.org
Similar Local Cases
#1963663 RESOLVED Certificate Problem Report Opened 2025-04-30 · Closed 2025-06-12 · 69% similar
Certigna: Multiple Reserved Certificate Policy Identifiers in CA certificates
#1685142 RESOLVED Certificate Problem Report Opened 2021-01-05 · Closed 2023-02-22 · 56% similar
Dhimyotis / Certigna: Failure to revoke in the timeline specified by the BRs
#1955365 RESOLVED Certificate Problem Report Opened 2025-03-20 · Closed 2025-05-19 · 55% similar
Apple: Public Key Reuse
#1950574 RESOLVED Certificate Problem Report Opened 2025-02-26 · Closed 2025-09-15 · 54% similar
SECOM: S/MIME CA Modified Opinion Report of Cybertrust Japan (CTJ)
#2025318 RESOLVED Certificate Problem Report Opened 2026-03-23 · Closed 2026-05-26 · 53% similar
certSIGN: delay in updating a Bugzilla ticket
#1886442 RESOLVED Certificate Problem Report Opened 2024-03-20 · Closed 2024-06-01 · 53% similar
Certigna: Revocation delay for TLS certificates with basic constraint not marked as critical
#1900654 RESOLVED Certificate Problem Report Opened 2024-06-04 · Closed 2024-08-28 · 51% similar
Certigna: ARL without reasoncode for recent revoked CA certificates
#2004732 RESOLVED Certificate Problem Report Opened 2025-12-08 · Closed 2026-01-05 · 49% similar
Certigna: AIA CA issuer field pointing to PEM encoded cert

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action