← Certigna cases
Bugzilla #2047843 Ca Certificate Compliance Problem Reporting Failure Revocation Issue

Certigna: Pre-certificates not recognised by the OCSP responder

RESOLVED FIXED Certigna
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The bug thread documents an incident where Certigna’s OCSP responder does not recognise pre-certificates that were issued but for which no final leaf certificate was generated. The disclosure source is stated as a third party via a Certificate Problem Report. Certigna reported a non-compliance period from 2024-05-13 to 2026-06-19, with no impact identified on certificates and totals of 0 TLS certificates and 5 precertificates. Certigna stated that it revoked two still-valid pre-certificates and updated the CRL and OCSP responder on 2026-06-17. Certigna also updated its TLS certificate issuance process and technical procedures on 2026-06-18 to revoke pre-certificates when the final DNS CAA check fails, and raised staff awareness of the workflow changes on 2026-06-19. On 2026-07-01, Certigna submitted a report closure summary stating all action items were completed, and CCADB issued a final call for comments before closure. The bug is currently marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-19 19:25 UTC Revised: 2026-07-12 06:01 UTC Confidence: 0.62 4 comments
Chronology
  1. A pre-certificate was issued where the final DNS CAA check was invalid, preventing generation of the associated final certificate.
  2. Certigna received third-party notification (via a Certificate Problem Report) that its OCSP responder did not recognise two certificates.
  3. Certigna revoked two still-valid pre-certificates and updated the CRL and OCSP responder.
  4. Certigna updated its TLS certificate issuance process and technical procedures to revoke pre-certificates when the final DNS CAA check fails.
  5. Certigna raised staff awareness of the updated procedures and workflow.
  6. Certigna submitted a closure summary requesting closure after stating all action items were completed.
Thread Activity
  1. Dhimyotis representative — Posted a preliminary incident report stating that pre-certificates without a final leaf certificate are not recognised by Certigna’s OCSP responder and that disclosure came from a third party via a Certificate Problem Report.
  2. Dhimyotis representative — Posted the full incident report with timeline, stated no impact, counts (0 TLS certificates, 5 precertificates), revocation of two still-valid pre-certificates, and process/procedure updates.
  3. Dhimyotis representative — Submitted a report closure summary describing the root cause and remediation and requesting closure after stating all action items were completed.
  4. CCADB representative — Issued a final call for comments/questions, stating the incident report would be closed on approximately 2026-07-08 if no further input was received.
Participants
Dhimyotis representative CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2056663 ASSIGNED Ca Certificate Compliance Externally Reported Incident Certificate Misissuance Problem Reporting Failure Opened 2026-07-21 Still Open · 76% similar
DigiCert: EVG CA profile compliance
#2053131 ASSIGNED Ca Certificate Compliance Incident Externally Reported Incident Problem Reporting Failure Opened 2026-07-07 Still Open · 72% similar
TunTrust: OCSP responder "Unknown" of one Pre-certificate
#1705657 RESOLVED Ca Certificate Compliance Revocation Issue Opened 2021-04-16 · Closed 2023-02-22 · 71% similar
KIR S.A.: Many certificates with OCSP Unknown
#2007219 RESOLVED Ca Certificate Compliance Opened 2025-12-20 · Closed 2026-02-17 · 70% similar
DigiCert: Some certificates issued with CRLDPs that don’t exactly match CCADB disclosures
#2032485 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-04-16 · Closed 2026-05-04 · 70% similar
DigiCert: Misissuance detected by PKIMetal
#2004733 RESOLVED Ca Certificate Compliance Opened 2025-12-08 · Closed 2026-01-15 · 70% similar
NAVER Cloud Trust Services: CA Certificate not published in DER Encoded Format
#2058918 ASSIGNED Ca Certificate Compliance Externally Reported Incident Certificate Misissuance Revocation Issue Opened 2026-07-29 Still Open · 69% similar
CFCA: Incorrect countryName values in OV subscriber certificates
#2004668 RESOLVED Ca Certificate Compliance Opened 2025-12-08 · Closed 2026-01-20 · 69% similar
Telekom Security: Root-CA certificates published in PEM encoded format

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action