← Disig, a.s. cases
Bugzilla #2056087 Ca Certificate Compliance Incident Certificate Misissuance Delayed Revocation Audit Finding

Disig CP/CPS keyUsage misstatement incident; all affected certificates revoked and closure summary requested

ASSIGNED Disig, a.s.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns Disig’s TLS Subscriber Certificates and a mismatch between its published CP/CPS and its issuance practice for the keyUsage criticality statement. The issue was first reported by a third party, and Disig initially described it as a documentation-only matter before accepting that the CP/CPS is a binding commitment and that the certificates were not issued in accordance with it. Disig published amended CP/CPS v7.3 on 2026-07-20 and later revoked all valid affected TLS certificates on 2026-07-23, with a CRL published afterward. Chrome Root Program asked Disig to answer questions about the review process, revocation timing, and audit procedures, and Disig relayed the auditor’s response that comprehensive cross-parameter comparisons had not been explicitly integrated into past audit cycles. Disig later said the policy-to-profile linting tool was completed and a formal SOP was published for future CP/CPS releases. On 2026-09-04, Disig requested that the incident be closed, and on 2026-09-05 CCADB asked for that request to be accompanied by a closure summary. The bug remains ASSIGNED.

Model: gpt-5.4-mini Generated: 2026-07-26 06:23 UTC Revised: 2026-09-06 06:02 UTC Confidence: 0.96 25 comments
Chronology
  1. Disig’s CP update changed the narrative text for keyUsage criticality from critical to non-critical.
  2. TLS BR v2.0.0 made keyUsage criticality mandatory, but Disig’s CP/CPS text remained uncorrected.
  3. A third party reported the CP/CPS discrepancy to Disig.
  4. Disig published amended CP/CPS v7.3 correcting the narrative text.
  5. Disig revoked 356 valid TLS certificates issued under the conflicting CP/CPS.
  6. Disig completed the policy-to-profile linting tool and published a formal SOP for future CP/CPS releases.
  7. Disig requested that the incident be closed.
Thread Activity
  1. Disig, a.s. — Disig filed a preliminary incident report describing the issue as a CP/CPS misstatement and saying the issued certificates were technically compliant.
  2. Google representative — Chrome Root Program said the case should not be treated as documentation-only and asked Disig to revise its report and address revocation and review questions.
  3. Disig, a.s. — Disig accepted that the CP/CPS is a binding commitment, published an amended CP/CPS, and submitted a revised full incident report.
  4. Sectigo — Sectigo asked about the issuance pause and the difference between this case and other large revocation incidents.
  5. Google representative — Chrome Root Program asked Disig to answer specific questions about deadlines, review processes, and audit procedures.
  6. Disig, a.s. — Disig answered questions about its lack of automated CP/CPS conformance checks and said it relied on manual review and BR-focused linters.
  7. Disig, a.s. — Disig stated that all valid affected TLS certificates had been revoked and attached the revocation list and CRL.
  8. Disig, a.s. — Disig relayed the auditor’s statement that the issue was caused by human error and that future audits would use a more detailed checklist and comprehensive comparison.
  9. Google representative — Chrome Root Program asked for clarification on the procedures used in the past three audit cycles.
  10. Disig, a.s. — Disig said it had contacted its auditor and was waiting for a response while the auditor was on vacation.
  11. Disig, a.s. — Disig said it was still testing its compliance-checking application and still waiting for the auditor’s response.
  12. Disig, a.s. — Disig relayed the auditor’s response that comprehensive cross-parameter comparisons were not explicitly integrated into the past audit cycles and that the audit methodology had been updated.
  13. Disig, a.s. — Disig said the policy-to-profile linting tool was completed and a formal SOP was published for future CP/CPS releases.
  14. Disig, a.s. — Disig requested that the incident be closed because all action items were completed and there had been no further comments for seven days.
  15. CCADB representative — CCADB asked Disig to accompany the closure request with a closure summary.
Participants
Disig, a.s. Google representative Sectigo CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1977253 RESOLVED Certificate Misissuance Opened 2025-07-14 · Closed 2025-09-15 · 83% similar
Sectigo: OV reuse data applied for wrong organization
#2032473 RESOLVED Ca Certificate Compliance Incident Externally Reported Incident Certificate Misissuance Opened 2026-04-16 · Closed 2026-08-08 · 79% similar
CCA India: Misissuance detected by PKIMetal
#2062202 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-08-10 Still Open · 78% similar
Sectigo: jurisdictionCountry versus organizationIdentifier mismatch in QWAC
#2055551 ASSIGNED Certificate Misissuance Self Reported Incident Externally Reported Incident Policy Document Issue Opened 2026-07-16 Still Open · 78% similar
HARICA: Issuance of Server TLS Certificates with id-kp-clientAuth KeyPurposeID against CP/CPS
#2044023 RESOLVED Certificate Misissuance Self Reported Incident Remediation Tracking Opened By Ca Opened 2026-06-01 · Closed 2026-07-02 · 78% similar
Asseco DS / Certum: Cross-Certificates subject encoding discrepancy
#1970259 RESOLVED Certificate Misissuance Incident Self Reported Incident Opened 2025-06-03 · Closed 2025-08-26 · 77% similar
GoDaddy: Precertificates incorrectly logged to DigiCert SCT Logs
#2023458 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-03-15 · Closed 2026-07-31 · 77% similar
D-Trust: TLS Precertificates Exceeding the Maximum Validity Period Allowed by the TLS Baseline Requirements
#2012326 RESOLVED Certificate Misissuance Opened 2026-01-25 · Closed 2026-02-27 · 75% similar
FNMT: Issuance of certificate using keys previously reported as compromised

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action