Disig CP/CPS misstatement about keyUsage criticality for TLS certificates
This case concerns Disig’s published CP/CPS text for TLS Subscriber Certificates, which incorrectly stated that the keyUsage extension was non-critical even though Disig’s technical issuance profiles enforced it as critical. The issue was first reported by a third party, and Disig initially described it as a documentation-only incident before revising its report after Mozilla and Chrome Root Program feedback. Disig then acknowledged that certificates issued under the conflicting CP/CPS were not issued in accordance with its binding CP/CPS and that this triggered revocation obligations under the Baseline Requirements. Disig published an amended CP/CPS v7.3, paused issuance briefly, and later reported revoking 356 valid affected TLS certificates on 2026-07-23. The thread also records follow-up questions about review controls, audit procedures, and why the discrepancy was not caught earlier. The bug remains assigned to Disig staff.
- Disig’s CP text was updated to say keyUsage was non-critical for TLS certificates.
- TLS BR v2.0.0 made keyUsage criticality mandatory, but Disig’s CP/CPS text remained uncorrected.
- A third party reported the CP/CPS discrepancy to Disig.
- Disig published amended CP/CPS v7.3 and later reported revocation planning for affected certificates.
- Disig revoked 356 valid TLS certificates issued under the conflicting CP/CPS.
- Disig, a.s. — Disig filed a preliminary incident report describing the issue as a CP/CPS misstatement and saying the certificates were technically compliant.
- Google representative — Chrome Root Program said the case should not be treated as documentation-only and asked Disig to revise its report and address revocation and review questions.
- Disig, a.s. — Disig accepted that the CP/CPS is a binding commitment, published an amended CP/CPS, and submitted a revised full incident report.
- Sectigo — Sectigo asked about the issuance pause and the difference between this case and other large revocation incidents.
- Google representative — Chrome Root Program asked Disig to answer specific questions about deadlines, review processes, and audit procedures.
- Disig, a.s. — Disig answered questions about its lack of automated CP/CPS conformance checks and said it relied on manual review and BR-focused linters.
- Disig, a.s. — Disig stated that all valid affected TLS certificates had been revoked and attached the revocation list and CRL.