Certigna: Subscriber certificate with EKU clientAuth only
Certigna disclosed an incident involving the issuance of client authentication certificates that only included the EKU clientAuth without the required serverAuth EKU or CA/Browser Forum reserved policy identifier. This issue was raised by Sectigo, prompting Certigna to halt the issuance of such certificates immediately on August 19, 2025. A total of 3,438 certificates were identified as affected, with 681 revoked through a mass revocation script. Certigna has committed to transitioning to a new dedicated CA for client authentication certificates and has completed all action items related to this incident. The incident has been resolved with all affected certificates revoked.
- Issuance of clientAuth certificates halted following compliance concerns raised by Sectigo.
- All affected clientAuth certificates were revoked.
- Certigna — Opened a Preliminary Incident Report regarding clientAuth-only certificates.
- Google representative — Raised concerns about policy chaining and compliance with TLS BRs.
- Certigna — Provided details on the historical authority's OIDs and confirmed the suspension of clientAuth issuance.
- Certigna — Summarized the incident closure, detailing root causes and remediation actions.
- CCADB representative — Final call for comments on the Incident Report before closure.