← Disig, a.s. cases
Bugzilla #2056087 Ca Certificate Compliance Incident Externally Reported Incident Certificate Misissuance Revocation Issue

Disig CP/CPS misstatement about keyUsage criticality for TLS certificates

ASSIGNED Disig, a.s.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns Disig’s published CP/CPS text for TLS Subscriber Certificates, which incorrectly stated that the keyUsage extension was non-critical even though Disig’s technical issuance profiles enforced it as critical. The issue was first reported by a third party, and Disig initially described it as a documentation-only incident before revising its report after Mozilla and Chrome Root Program feedback. Disig then acknowledged that certificates issued under the conflicting CP/CPS were not issued in accordance with its binding CP/CPS and that this triggered revocation obligations under the Baseline Requirements. Disig published an amended CP/CPS v7.3, paused issuance briefly, and later reported revoking 356 valid affected TLS certificates on 2026-07-23. The thread also records follow-up questions about review controls, audit procedures, and why the discrepancy was not caught earlier. The bug remains assigned to Disig staff.

Model: gpt-5.4-mini Generated: 2026-07-26 06:23 UTC Confidence: 0.93 16 comments
Chronology
  1. Disig’s CP text was updated to say keyUsage was non-critical for TLS certificates.
  2. TLS BR v2.0.0 made keyUsage criticality mandatory, but Disig’s CP/CPS text remained uncorrected.
  3. A third party reported the CP/CPS discrepancy to Disig.
  4. Disig published amended CP/CPS v7.3 and later reported revocation planning for affected certificates.
  5. Disig revoked 356 valid TLS certificates issued under the conflicting CP/CPS.
Thread Activity
  1. Disig, a.s. — Disig filed a preliminary incident report describing the issue as a CP/CPS misstatement and saying the certificates were technically compliant.
  2. Google representative — Chrome Root Program said the case should not be treated as documentation-only and asked Disig to revise its report and address revocation and review questions.
  3. Disig, a.s. — Disig accepted that the CP/CPS is a binding commitment, published an amended CP/CPS, and submitted a revised full incident report.
  4. Sectigo — Sectigo asked about the issuance pause and the difference between this case and other large revocation incidents.
  5. Google representative — Chrome Root Program asked Disig to answer specific questions about deadlines, review processes, and audit procedures.
  6. Disig, a.s. — Disig answered questions about its lack of automated CP/CPS conformance checks and said it relied on manual review and BR-focused linters.
  7. Disig, a.s. — Disig stated that all valid affected TLS certificates had been revoked and attached the revocation list and CRL.
Participants
Disig, a.s. Google representative Sectigo
Related Bugzilla IDs Mentioned
Similar Local Cases
#2055551 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-07-16 Still Open · 80% similar
HARICA: Issuance of Server TLS Certificates with id-kp-clientAuth KeyPurposeID against CP/CPS
#1902748 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-06-14 · Closed 2026-06-10 · 77% similar
Sectigo: QWAC certificates issued with incorrect subject:organizationIdentifier attribute value
#1977253 RESOLVED Certificate Misissuance Opened 2025-07-14 · Closed 2025-09-15 · 75% similar
Sectigo: OV reuse data applied for wrong organization
#2032468 ASSIGNED Ca Certificate Compliance Certificate Misissuance Problem Reporting Failure Audit Finding Opened 2026-04-16 Still Open · 72% similar
VISA: Misissuance detected by PKIMetal
#1691704 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-02-09 · Closed 2023-02-22 · 72% similar
SwissSign: Certificate with key length 4098 bit
#2056882 UNCONFIRMED Ca Certificate Compliance Certificate Misissuance Externally Reported Incident Problem Reporting Failure Opened 2026-07-22 Still Open · 71% similar
D-Trust: EV Subordinate CA missing required cabfOrganizationIdentifier extension
#1391867 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-08-19 · Closed 2023-02-22 · 71% similar
Let's Encrypt: Non-BR-Compliant Certificate Issuance
#2032473 ASSIGNED Ca Certificate Compliance Incident Externally Reported Incident Certificate Misissuance Opened 2026-04-16 Still Open · 71% similar
CCA India: Misissuance detected by PKIMetal

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action