← Certigna cases
Bugzilla #2047843 Ca Certificate Compliance Problem Reporting Failure Revocation Issue

Certigna: Pre-certificates not recognised by the OCSP responder

RESOLVED FIXED Certigna
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The bug thread documents an incident where Certigna’s OCSP responder does not recognise pre-certificates that were issued but for which no final leaf certificate was generated. The disclosure source is stated as a third party via a Certificate Problem Report. Certigna reported a non-compliance period from 2024-05-13 to 2026-06-19, with no impact identified on certificates and totals of 0 TLS certificates and 5 precertificates. Certigna stated that it revoked two still-valid pre-certificates and updated the CRL and OCSP responder on 2026-06-17. Certigna also updated its TLS certificate issuance process and technical procedures on 2026-06-18 to revoke pre-certificates when the final DNS CAA check fails, and raised staff awareness of the workflow changes on 2026-06-19. On 2026-07-01, Certigna submitted a report closure summary stating all action items were completed, and CCADB issued a final call for comments before closure. The bug is currently marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-19 19:25 UTC Revised: 2026-07-12 06:01 UTC Confidence: 0.62 4 comments
Chronology
  1. A pre-certificate was issued where the final DNS CAA check was invalid, preventing generation of the associated final certificate.
  2. Certigna received third-party notification (via a Certificate Problem Report) that its OCSP responder did not recognise two certificates.
  3. Certigna revoked two still-valid pre-certificates and updated the CRL and OCSP responder.
  4. Certigna updated its TLS certificate issuance process and technical procedures to revoke pre-certificates when the final DNS CAA check fails.
  5. Certigna raised staff awareness of the updated procedures and workflow.
  6. Certigna submitted a closure summary requesting closure after stating all action items were completed.
Thread Activity
  1. Dhimyotis representative — Posted a preliminary incident report stating that pre-certificates without a final leaf certificate are not recognised by Certigna’s OCSP responder and that disclosure came from a third party via a Certificate Problem Report.
  2. Dhimyotis representative — Posted the full incident report with timeline, stated no impact, counts (0 TLS certificates, 5 precertificates), revocation of two still-valid pre-certificates, and process/procedure updates.
  3. Dhimyotis representative — Submitted a report closure summary describing the root cause and remediation and requesting closure after stating all action items were completed.
  4. CCADB representative — Issued a final call for comments/questions, stating the incident report would be closed on approximately 2026-07-08 if no further input was received.
Participants
Dhimyotis representative CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2053131 RESOLVED Ca Certificate Compliance Externally Reported Incident Problem Reporting Failure Repository Issue Opened 2026-07-07 · Closed 2026-08-18 · 83% similar
TunTrust: OCSP responder "Unknown" of one Pre-certificate
#2056663 RESOLVED Ca Certificate Compliance Externally Reported Incident Problem Reporting Failure Certificate Misissuance Opened 2026-07-21 · Closed 2026-08-10 · 77% similar
DigiCert: EVG CA profile compliance
#2060581 ASSIGNED Ca Certificate Compliance Externally Reported Incident Certificate Misissuance Revocation Issue Opened 2026-08-04 Still Open · 72% similar
Actalis: Issuance of Server TLS Certificates with id-kp-clientAuth against CPS
#2061178 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-08-06 Still Open · 71% similar
Asseco DS / Certum: Incorrect Country in certificate
#1705657 RESOLVED Ca Certificate Compliance Revocation Issue Opened 2021-04-16 · Closed 2023-02-22 · 71% similar
KIR S.A.: Many certificates with OCSP Unknown
#2065895 ASSIGNED Ca Certificate Compliance Externally Reported Incident Certificate Misissuance Revocation Issue Opened 2026-08-23 Still Open · 70% similar
GlobalSign: StateOrProvince and LocalityName value inconsistency
#2057318 ASSIGNED Externally Reported Incident Certificate Misissuance Problem Reporting Failure Opened 2026-07-23 Still Open · 70% similar
GlobalSign: Unicode replacement character issue in Subject
#2065634 ASSIGNED Ca Certificate Compliance Externally Reported Incident Certificate Misissuance Revocation Issue Opened 2026-08-21 Still Open · 70% similar
SSL.com: Invalid combinations of countryName, stateOrProvinceName, and localityName attributes

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action