← D-TRUST cases
Bugzilla #2023458 Ca Certificate Compliance Certificate Misissuance

D-Trust: 19 TLS precertificates issued with validity > 200-day maximum (TLS BR 6.3.2)

RESOLVED FIXED D-TRUST
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

D-Trust reported that it mis-issued 19 TLS precertificates with validity periods exceeding the 200-day maximum allowed by the TLS Baseline Requirements (Section 6.3.2), as introduced by Ballot SC-81. The issue was identified internally via automated linting checks performed after precertificate issuance and CT submission; the linting detected the non-compliant validity period and blocked issuance of the corresponding final TLS end-entity certificates. D-Trust stated that the pre-certificates were signed by the Issuing CA and submitted to CT logs, and that all affected pre-certificates were revoked on 2026-03-15 15:34 UTC. D-Trust also performed an emergency modification of the affected product configuration to prevent further non-compliant pre-certificates, and later implemented corrective changes in the issuance path by 2026-03-15 21:45 UTC. In the later full incident report, D-Trust described contributing factors including failure to execute/enforce QA verification steps before productive deployment, a deficient approval process that did not verify required pre-deployment QA checks, and a delayed implementation timeline due to compressed deadlines. D-Trust requested closure after completing immediate remediation actions and completing disclosed action items.

Model: gpt-5.4-nano Generated: 2026-06-13 21:35 UTC Revised: 2026-06-16 10:29 UTC Confidence: 0.90 32 comments
Chronology
  1. D-Trust issued 19 non-compliant TLS precertificates with validity exceeding the 200-day maximum; automated linting later blocked final certificate issuance and the precertificates were revoked.
Thread Activity
  1. Bdr representative — Opened a preliminary incident report stating D-Trust identified internally that 19 TLS precertificates exceeded the 200-day maximum validity and that all affected precertificates were revoked after identification.
  2. D-Trust — Submitted a full incident report describing the mis-issuance, stating pre-certificates were CT-logged, final certificates were not issued due to workflow blocking, and that all affected pre-certificates were revoked on 2026-03-15 15:34 UTC.
  3. D-Trust — Provided additional analysis stating D-Trust stopped all issuance from the affected part of its PKI as of 2026-04-02 08:45 UTC and noted a separate preliminary incident report would be filed for a broader compliance gap.
  4. Bdr representative — Noted that a new incident report was opened in a separate bug and provided its Bugzilla link.
  5. Bdr representative — Answered questions about the updated notAfter computation logic and clarified that only validity-period enforcement was changed in the RA system.
  6. D-Trust — Posted the report closure summary, including remediation (revocation completed by 16:34) and root-cause contributing factors, and requested closure after completing action items.
  7. CCADB representative — Issued a final call for comments/questions and stated the incident report would be closed approximately 2026-06-01.
Participants
Bdr representative HARICA CCADB representative Sectigo Mozilla representative D-Trust Mm representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1390990 RESOLVED Certificate Misissuance Delayed Revocation Opened 2017-08-16 · Closed 2023-02-22 · 89% similar
D-TRUST: Non-BR-Compliant Certificate Issuance
#1075952 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2014-10-01 · Closed 2022-11-14 · 88% similar
D-Trust: issuing 1024 bit certificates
#2056882 UNCONFIRMED Ca Certificate Compliance Certificate Misissuance Externally Reported Incident Problem Reporting Failure Opened 2026-07-22 Still Open · 87% similar
D-Trust: EV Subordinate CA missing required cabfOrganizationIdentifier extension
#1599561 RESOLVED Certificate Misissuance Opened 2019-11-26 · Closed 2023-02-22 · 87% similar
D-TRUST: EV certificates with incorrectly used businessCategory entry
#1939809 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-01-03 · Closed 2026-06-12 · 87% similar
D-Trust: QCStatement with http link of PKI Disclosure Statements
#1691117 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2021-02-05 · Closed 2023-02-22 · 86% similar
D-TRUST: Certificate with RSA key where modulus is not divisible by 8
#1677737 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-11-17 · Closed 2023-02-22 · 85% similar
SwissSign: duplicate serial number
#1653504 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-07-17 · Closed 2023-02-22 · 85% similar
Sectigo: Certificates with RSA keys where modulus is not divisible by 8

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action