← Izenpe S.A. cases
Bugzilla #1996857
Certificate Problem Report
IZENPE: not allowed Key Usage in ocsp responder certificate
RESOLVED
FIXED
Izenpe S.A.
AI Summary
Izenpe S.A. reported a compliance issue regarding their OCSP responder certificates, which included the 'nonRepudiation' key usage contrary to the Baseline Requirements (BR) that only permit 'digitalSignature'. This non-compliance was identified on October 28, 2025, during a review of all profiles defined in the BRs. The issue arose due to a failure to notice the change in the BRs when they were updated on September 15, 2023. Izenpe has since issued new OCSP responder certificates that comply with the BRs and have begun signing OCSP responses with the corrected key usage.
Chronology
- BR revision 2.0.0 comes into effect.
- Non-compliance identified.
- New OCSP responder certificates to be issued.
- New OCSP responder certificates start signing OCSP responses.
Participants
David Fernandez
James Kasten
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
Izenpe: Not allowed Qualifier ID OID on Certificate Policies extension
Izenpe: Duplicate attribute in Subject
Izenpe: CRL and ARL exceed validity period value by one second
Izenpe: Not allowed Qualifier ID OID on Certificate Policies extension of Precertificates
IZENPE: Failed to respond a Certificate Problem Report within 24 hours and create a preliminary report in 72 hours
Izenpe: EV certificate with various issues
Izenpe: Intermediate CA certificates not listed in audit report
Izenpe: Certificates not disclosed in CCADB