Disig CP/CPS keyUsage misstatement incident; all affected certificates revoked and closure summary requested
This case concerns Disig’s TLS Subscriber Certificates and a mismatch between its published CP/CPS and its issuance practice for the keyUsage criticality statement. The issue was first reported by a third party, and Disig initially described it as a documentation-only matter before accepting that the CP/CPS is a binding commitment and that the certificates were not issued in accordance with it. Disig published amended CP/CPS v7.3 on 2026-07-20 and later revoked all valid affected TLS certificates on 2026-07-23, with a CRL published afterward. Chrome Root Program asked Disig to answer questions about the review process, revocation timing, and audit procedures, and Disig relayed the auditor’s response that comprehensive cross-parameter comparisons had not been explicitly integrated into past audit cycles. Disig later said the policy-to-profile linting tool was completed and a formal SOP was published for future CP/CPS releases. On 2026-09-04, Disig requested that the incident be closed, and on 2026-09-05 CCADB asked for that request to be accompanied by a closure summary. The bug remains ASSIGNED.
- Disig’s CP update changed the narrative text for keyUsage criticality from critical to non-critical.
- TLS BR v2.0.0 made keyUsage criticality mandatory, but Disig’s CP/CPS text remained uncorrected.
- A third party reported the CP/CPS discrepancy to Disig.
- Disig published amended CP/CPS v7.3 correcting the narrative text.
- Disig revoked 356 valid TLS certificates issued under the conflicting CP/CPS.
- Disig completed the policy-to-profile linting tool and published a formal SOP for future CP/CPS releases.
- Disig requested that the incident be closed.
- Disig, a.s. — Disig filed a preliminary incident report describing the issue as a CP/CPS misstatement and saying the issued certificates were technically compliant.
- Google representative — Chrome Root Program said the case should not be treated as documentation-only and asked Disig to revise its report and address revocation and review questions.
- Disig, a.s. — Disig accepted that the CP/CPS is a binding commitment, published an amended CP/CPS, and submitted a revised full incident report.
- Sectigo — Sectigo asked about the issuance pause and the difference between this case and other large revocation incidents.
- Google representative — Chrome Root Program asked Disig to answer specific questions about deadlines, review processes, and audit procedures.
- Disig, a.s. — Disig answered questions about its lack of automated CP/CPS conformance checks and said it relied on manual review and BR-focused linters.
- Disig, a.s. — Disig stated that all valid affected TLS certificates had been revoked and attached the revocation list and CRL.
- Disig, a.s. — Disig relayed the auditor’s statement that the issue was caused by human error and that future audits would use a more detailed checklist and comprehensive comparison.
- Google representative — Chrome Root Program asked for clarification on the procedures used in the past three audit cycles.
- Disig, a.s. — Disig said it had contacted its auditor and was waiting for a response while the auditor was on vacation.
- Disig, a.s. — Disig said it was still testing its compliance-checking application and still waiting for the auditor’s response.
- Disig, a.s. — Disig relayed the auditor’s response that comprehensive cross-parameter comparisons were not explicitly integrated into the past audit cycles and that the audit methodology had been updated.
- Disig, a.s. — Disig said the policy-to-profile linting tool was completed and a formal SOP was published for future CP/CPS releases.
- Disig, a.s. — Disig requested that the incident be closed because all action items were completed and there had been no further comments for seven days.
- CCADB representative — CCADB asked Disig to accompany the closure request with a closure summary.