988633 |
GoDaddy: improperly encoded certificate issued by Go Daddy Secure Certification Authority |
RESOLVED |
FIXED |
2023-02-22T18:21:18Z |
1017157 |
DigiCert: no subject alternative name in Siemens certs |
RESOLVED |
FIXED |
2023-02-22T18:21:14Z |
1029147 |
[meta] Bug for Tracking BR Compliance Issues |
RESOLVED |
WORKSFORME |
2022-11-14T22:22:57Z |
1195115 |
Swisscom: certificates without DNS names in subjectAltName |
RESOLVED |
WONTFIX |
2022-11-14T22:22:57Z |
1262610 |
DigiCert: ECCE 001 issuing certificates without subject alternative name extension |
RESOLVED |
FIXED |
2023-02-22T18:19:26Z |
1267049 |
Izenpe: EV certificate with various issues |
RESOLVED |
FIXED |
2023-02-22T18:21:21Z |
1304895 |
DigiCert: TI Trust Technologies Global CA issued certificate with no subject alternative name extension |
RESOLVED |
FIXED |
2023-02-22T18:28:19Z |
1319609 |
Let's Encrypt: certs issued contrary to CPS due to incomplete blocklist |
RESOLVED |
FIXED |
2023-02-22T18:21:22Z |
1330482 |
GoDaddy: New GoDaddy incorrect issuance bug appears to be regression of 2010 issue |
RESOLVED |
INCOMPLETE |
2023-02-22T18:21:20Z |
1334377 |
Symantec: Mis-issued test certificates by CrossCert |
RESOLVED |
FIXED |
2023-02-22T18:21:31Z |
1335132 |
DigiCert: Verizon mis-issued test certificates |
RESOLVED |
FIXED |
2023-02-22T18:19:52Z |
1339339 |
DigiCert: Non-BR Compliant Certificates - missing CP/CPS OID |
RESOLVED |
FIXED |
2023-02-22T18:19:41Z |
1341014 |
GoDaddy: Action Items |
RESOLVED |
FIXED |
2023-02-22T18:21:17Z |
1353827 |
DigiCert: DigiCert issued cert with CN too long |
RESOLVED |
FIXED |
2023-02-22T18:21:13Z |
1353833 |
GlobalSign: Incapsula issued a certificate for non-existing domain (testslsslfeb20.me) |
RESOLVED |
FIXED |
2023-02-22T18:21:16Z |
1353838 |
Trustis: SHA-1 serverAuth cert issued in November 2016 |
RESOLVED |
FIXED |
2023-02-22T18:21:32Z |
1357067 |
Camerfirma: certs with duplicate SANs and without localityName or stateOrProvinceName |
RESOLVED |
FIXED |
2023-02-22T18:21:09Z |
1367842 |
TurkTrust: Non-audited, non-technically-constrained intermediate certs |
RESOLVED |
FIXED |
2023-02-22T18:13:19Z |
1368171 |
Firmaprofesional: Non-audited, non-technically-constrained intermediate certificates |
RESOLVED |
FIXED |
2024-06-30T20:08:03Z |
1368176 |
DigiCert: Non-audited, non-technically-constrained intermediate certificates |
RESOLVED |
FIXED |
2024-06-30T20:06:13Z |
1368178 |
Symantec: Non-audited, non-technically-constrained intermediate certificate |
RESOLVED |
FIXED |
2024-06-30T20:16:31Z |
1369342 |
StartCom: 'un-revoking' intermediate certificates |
RESOLVED |
FIXED |
2023-02-22T18:21:28Z |
1369359 |
StartCom: mis-issuance of certs with unvalidated domain names and bogus field values |
RESOLVED |
FIXED |
2023-02-22T18:21:29Z |
1374381 |
SwissSign: BRs require full annual audits |
RESOLVED |
FIXED |
2023-02-22T18:24:44Z |
1378074 |
Private keys for certificates exposed through their web server |
RESOLVED |
FIXED |
2023-02-22T18:21:25Z |
1386891 |
Certinomis: Cross-signing of StartCom intermediate certs, and delay in reporting it in CCADB |
RESOLVED |
FIXED |
2023-02-22T18:17:48Z |
1386894 |
StartCom: Non-BR-Compliant Certificate Issuance -- adding Certnomis intermediates to OneCRL |
RESOLVED |
DUPLICATE |
2023-02-22T18:21:30Z |
1389172 |
DigiCert: Certificate Issues Identified on the Mailing List |
RESOLVED |
FIXED |
2023-02-22T18:21:12Z |
1390974 |
Actalis: Non-BR-Compliant Certificate Issuance |
RESOLVED |
FIXED |
2023-02-22T18:12:02Z |
1390977 |
Camerfirma: Non-BR-Compliant Certificate Issuance |
RESOLVED |
FIXED |
2023-02-22T18:24:39Z |
1390978 |
Certinomis: Non-BR-Compliant Certificate Issuance |
RESOLVED |
FIXED |
2023-02-22T18:17:49Z |
1390979 |
certSIGN: Non-BR-Compliant Certificate Issuance |
RESOLVED |
FIXED |
2023-02-22T18:16:07Z |
1390981 |
Comodo: Non-BR-Compliant Certificate Issuance |
RESOLVED |
FIXED |
2023-02-22T18:24:57Z |
1390988 |
Consorci AOC: Non-BR-Compliant Certificate Issuance |
RESOLVED |
FIXED |
2023-02-22T18:17:43Z |
1390990 |
D-TRUST: Non-BR-Compliant Certificate Issuance |
RESOLVED |
FIXED |
2023-02-22T18:14:37Z |
1390991 |
Disig: Non-BR-Compliant Certificate Issuance |
RESOLVED |
FIXED |
2023-02-22T18:24:06Z |
1390994 |
DocuSign/Keynectis: Non-BR-Compliant Certificate Issuance |
RESOLVED |
FIXED |
2023-02-22T18:17:17Z |
1390996 |
Entrust: Non-BR-Compliant Certificate Issuance |
RESOLVED |
FIXED |
2023-02-22T18:21:04Z |
1390997 |
GlobalSign: Non-BR-Compliant Certificate Issuance - metadata-only subject fields |
RESOLVED |
FIXED |
2023-02-22T18:21:35Z |
1390998 |
Kamu SM: Non-BR-Compliant Certificate Issuance |
RESOLVED |
FIXED |
2023-02-22T18:27:43Z |
1391000 |
IdenTrust: Non-BR-Compliant Certificate Issuance |
RESOLVED |
FIXED |
2023-02-22T18:28:03Z |
1391054 |
Izenpe: Non-BR-Compliant Certificate Issuance |
RESOLVED |
FIXED |
2023-02-22T18:23:31Z |
1391055 |
Microsec: Non-BR-Compliant Certificate Issuance |
RESOLVED |
FIXED |
2023-02-22T18:27:03Z |
1391056 |
NetLock: Non-BR-Compliant Certificate Issuance |
RESOLVED |
FIXED |
2023-02-22T18:27:56Z |
1391058 |
PROCERT: Non-BR-Compliant Certificate Issuance |
RESOLVED |
DUPLICATE |
2023-02-22T18:22:57Z |
1391063 |
QuoVadis: Non-BR-Compliant Certificate Issuance |
RESOLVED |
FIXED |
2023-02-22T18:26:08Z |
1391064 |
SECOM: Non-BR-Compliant Certificate Issuance |
RESOLVED |
FIXED |
2023-02-22T18:18:25Z |
1391066 |
SwissSign: Non-BR-Compliant Certificate Issuance |
RESOLVED |
FIXED |
2023-02-22T18:16:04Z |
1391067 |
Symantec: Non-BR-Compliant Certificate Issuance |
RESOLVED |
FIXED |
2023-02-22T18:26:45Z |
1391068 |
Taiwan-CA: Non-BR-Compliant Certificate Issuance |
RESOLVED |
FIXED |
2023-02-22T18:25:26Z |
1391074 |
T-Systems: Non-BR-Compliant Certificate Issuance |
RESOLVED |
FIXED |
2023-02-22T18:21:38Z |
1391087 |
Visa: Non-BR-Compliant Certificate Issuance |
RESOLVED |
FIXED |
2023-02-22T18:22:28Z |
1391089 |
WISeKey: Non-BR-Compliant Certificate Issuance |
RESOLVED |
FIXED |
2023-02-22T18:24:16Z |
1391429 |
GoDaddy: Non-BR-Compliant Certificate Issuance |
RESOLVED |
FIXED |
2024-02-27T10:44:09Z |
1391864 |
Staat der Nederlandend / PKIoverheid: Non-BR-Compliant Certificate Issuance |
RESOLVED |
FIXED |
2023-02-22T18:22:02Z |
1391867 |
Let's Encrypt: Non-BR-Compliant Certificate Issuance |
RESOLVED |
FIXED |
2023-02-22T18:18:55Z |
1393555 |
GlobalSign: Non-BR-Compliant Certificate Issuance -- double-dots in dnsName |
RESOLVED |
FIXED |
2023-02-22T18:21:36Z |
1393557 |
GlobalSign: Non-BR-Compliant Certificate Issuance -- RSA key smaller than 2048 bits |
RESOLVED |
FIXED |
2023-02-22T18:21:37Z |
1397830 |
EDICOM: Signing SHA-1 OCSP responses with unconstrained certificate |
RESOLVED |
FIXED |
2023-02-22T18:26:03Z |
1397832 |
GRCA: Signing SHA-1 OCSP responses with unconstrained certificate |
RESOLVED |
FIXED |
2023-02-22T18:18:07Z |
1397951 |
DigiCert / InfoCert: Insufficient Serial Number Entropy |
RESOLVED |
FIXED |
2023-02-22T18:19:06Z |
1397954 |
DigiCert / Siemens: Insufficient Serial Number Entropy |
RESOLVED |
FIXED |
2023-02-22T18:19:10Z |
1397957 |
DigiCert / CTJ: Metadata in OU fields, Reserved IP Address |
RESOLVED |
FIXED |
2023-02-22T18:19:05Z |
1397958 |
DigiCert / Terena: Metadata in OU fields |
RESOLVED |
FIXED |
2023-02-22T18:19:14Z |
1397960 |
DigiCert / Telecom Italia: Several Problems |
RESOLVED |
FIXED |
2023-02-22T18:19:13Z |
1397961 |
DigiCert / Justica: Invalid DNS names |
RESOLVED |
FIXED |
2023-02-22T18:19:08Z |
1397963 |
DigiCert / Wells Fargo: Invalid DNS names |
RESOLVED |
FIXED |
2023-02-22T18:19:16Z |
1397965 |
DigiCert / Swiss Government: CommonName not in SANs |
RESOLVED |
FIXED |
2023-02-22T18:19:11Z |
1397968 |
DigiCert / Verizon: Reserved/Intranet domain name |
RESOLVED |
DUPLICATE |
2023-02-22T18:19:15Z |
1397969 |
DigiCert / Inteso San Paulo: Double dot characters |
RESOLVED |
FIXED |
2023-02-22T18:19:07Z |
1398233 |
Sertifitseerimiskeskuse: Non-BR-Compliant OCSP Responders |
RESOLVED |
FIXED |
2023-02-22T18:22:52Z |
1398240 |
Firmaprofesional: Non-BR-Compliant OCSP Responders |
RESOLVED |
FIXED |
2023-02-22T18:15:57Z |
1398242 |
Disig: Non-BR-Compliant OCSP Responders |
RESOLVED |
FIXED |
2023-02-22T18:24:07Z |
1398243 |
certSIGN: Non-BR-Compliant OCSP Responders |
RESOLVED |
FIXED |
2023-02-22T18:16:09Z |
1398246 |
Consorci AOC: Non-BR-Compliant OCSP Responders |
RESOLVED |
FIXED |
2023-02-22T18:17:44Z |
1398247 |
DocuSign/Keynectis: Non-BR-Compliant OCSP Responders |
RESOLVED |
FIXED |
2023-02-22T18:17:18Z |
1398251 |
Staat der Nederlandend / PKIoverheid: Non-BR-Compliant OCSP Responders |
RESOLVED |
FIXED |
2023-02-22T18:22:03Z |
1398255 |
IdenTrust: Non-BR-Compliant OCSP Responders |
RESOLVED |
FIXED |
2023-02-22T18:28:04Z |
1398258 |
Izenpe: Non-BR-Compliant OCSP Responders |
RESOLVED |
FIXED |
2023-02-22T18:23:32Z |
1398259 |
SECOM: Non-BR-Compliant OCSP Responders |
RESOLVED |
FIXED |
2023-02-22T18:18:26Z |
1398261 |
Visa: Non-BR-Compliant OCSP Responders |
RESOLVED |
FIXED |
2023-02-22T18:22:29Z |
1398269 |
DigiCert: Non-BR-Compliant OCSP Responders |
RESOLVED |
FIXED |
2023-02-22T18:19:42Z |
1398427 |
Let's Encrypt: CAA Misissuances |
RESOLVED |
FIXED |
2023-02-22T18:18:48Z |
1398428 |
Amazon Trust Services: CAA Misissuances |
RESOLVED |
FIXED |
2023-02-22T18:24:33Z |
1398545 |
Comodo: CAA Misissuance |
RESOLVED |
FIXED |
2023-02-22T18:24:54Z |
1401211 |
NetLock: Non-BR-Compliant Certificate Issuance -- * in not the leftmost position in dnsName |
RESOLVED |
FIXED |
2023-02-22T18:27:57Z |
1401407 |
DigiCert: Mis-Issuance Rekey certificates |
RESOLVED |
FIXED |
2023-02-22T18:19:17Z |
1401486 |
T-Systems / DFN-PKI: cablint findings, follow up to T-Systems Bug 1391074 |
RESOLVED |
FIXED |
2023-02-22T18:21:40Z |
1404403 |
SwissSign: Two certs issued with same issuer and serial number |
RESOLVED |
FIXED |
2023-02-22T18:16:05Z |
1405815 |
Camerfirma: Certs issued with same issuer and serial number |
RESOLVED |
FIXED |
2023-02-22T18:24:38Z |
1405817 |
Actalis: Certs issued with same issuer and serial number |
RESOLVED |
FIXED |
2023-02-22T18:11:52Z |
1405826 |
Trustwave: Certs issued with same issuer and serial number |
RESOLVED |
FIXED |
2023-02-22T18:17:39Z |
1409735 |
DigiCert: RapidSSL CAA Mis-Issuance: Lookup failure on DNSSEC-signed zone |
RESOLVED |
FIXED |
2024-05-09T23:37:44Z |
1409760 |
StartCom: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record |
RESOLVED |
WONTFIX |
2022-11-14T22:22:57Z |
1409764 |
Asseco DS / Certum: CAA mis-issuance on critical flag and unknown CAA tag |
RESOLVED |
FIXED |
2023-02-22T18:12:45Z |
1409766 |
Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record |
RESOLVED |
FIXED |
2023-02-22T18:28:38Z |
1409859 |
Startcom: CAA Mis-Issuance: Lookup failure on DNSSEC-signed zone |
RESOLVED |
INVALID |
2024-05-09T23:38:31Z |
1410834 |
Comodo: CAA Mis-Issuance on basic test case |
RESOLVED |
FIXED |
2023-02-22T18:25:05Z |
1412950 |
Firmaprofesional: Insufficient Audit Statements |
RESOLVED |
FIXED |
2024-06-30T19:45:20Z |
1413761 |
DigiCert / Symantec: EV JOI Issue |
RESOLVED |
FIXED |
2023-02-22T18:19:53Z |
1417771 |
DigiCert: Symantec non-constrained/non-disclosed intermediate CA certificates |
RESOLVED |
FIXED |
2024-06-30T20:06:39Z |
1417777 |
DigiCert: Insufficient entropy in serial numbers |
RESOLVED |
FIXED |
2023-02-22T18:19:33Z |
1420766 |
Globalsign / AlphaSSL: CAA Mis-Issuance on mix of wildcard and non-wildcard DNS names in SAN |
RESOLVED |
INVALID |
2024-05-09T20:55:38Z |
1420858 |
Comodo: CAA Mis-Issuance on mix of wildcard and non-wildcard DNS names in SAN |
RESOLVED |
FIXED |
2023-02-22T18:24:53Z |
1420860 |
Asseco DS / Certum: CAA Mis-Issuance on mix of wildcard and non-wildcard DNS names in SAN |
RESOLVED |
FIXED |
2023-02-22T18:12:46Z |
1420861 |
DigiCert / Thawte: CAA Mis-Issuance on mix of wildcard and non-wildcard DNS names in SAN |
RESOLVED |
INVALID |
2024-05-09T21:01:30Z |
1420871 |
Camerfirma: Potential Mis-Issuance based on CAA records |
RESOLVED |
FIXED |
2023-02-22T18:24:41Z |
1420873 |
Comodo/cPanel: Potential Mis-Issuance based on CAA records (Sep 28, 2017) |
RESOLVED |
INVALID |
2022-11-14T22:22:57Z |
1423624 |
Comodo: CAA misissuances due to race condition |
RESOLVED |
FIXED |
2023-02-22T18:24:55Z |
1424305 |
DigiCert: Microsoft: Incident report for Microsoft Dynamics incident |
RESOLVED |
FIXED |
2023-02-22T18:19:38Z |
1425805 |
Consorci AOC: Insufficient Audit Statements |
RESOLVED |
FIXED |
2023-02-22T18:17:42Z |
1425998 |
Certinomis / Docapost: Non-BR-Compliant OCSP Responders |
RESOLVED |
FIXED |
2023-02-22T18:17:51Z |
1426009 |
T-Systems: Non-BR-Compliant OCSP Responders |
RESOLVED |
FIXED |
2023-02-22T18:21:39Z |
1426233 |
Camerfirma: Non-BR-Compliant OCSP Responders |
RESOLVED |
FIXED |
2023-02-22T18:24:40Z |
1426238 |
QuoVadis: Non-BR-Compliant OCSP Responder |
RESOLVED |
FIXED |
2023-02-22T18:26:11Z |
1426247 |
Telia: Non-BR-Compliant OCSP Responder |
RESOLVED |
FIXED |
2023-02-22T18:23:59Z |
1426249 |
Trustis: Non-Br-Compliant OCSP Responder |
RESOLVED |
FIXED |
2023-02-22T18:13:45Z |
1428832 |
Consorci AOC: Problem reporting mechanism for Consorci AOC points to URL with invalid cert |
RESOLVED |
FIXED |
2023-02-22T18:17:45Z |
1428877 |
SwissSign: Invalid DNSName in SAN |
RESOLVED |
FIXED |
2023-02-22T18:22:43Z |
1428891 |
Entrust: Non-BR-Compliant OCSP Responder |
RESOLVED |
FIXED |
2023-02-22T18:14:51Z |
1429639 |
DigiCert: BR 3.2.5 Validation of Authority Failure for OV Certs |
RESOLVED |
FIXED |
2023-02-22T18:19:22Z |
1430909 |
QuoVadis: Non-BR-Compliant issuance --improper characters in DNSName (BIT sub-CA) |
RESOLVED |
FIXED |
2023-02-22T18:26:10Z |
1431164 |
Camerfirma: Non-BR-Compliant Issuance - Non-printable characters in OU field |
RESOLVED |
FIXED |
2023-02-22T18:22:20Z |
1435770 |
Asseco DS / Certum: Non-BR-Compliant Issuance - Debian Weak Keys |
RESOLVED |
FIXED |
2023-02-22T18:12:48Z |
1436173 |
DigiCert: SCEE / Justica: Non-BR-Compliant Certificate Issuance |
RESOLVED |
FIXED |
2023-02-22T18:13:39Z |
1439123 |
GoDaddy: Failure to respond to January 2018 survey |
RESOLVED |
FIXED |
2023-02-22T18:16:37Z |
1439126 |
Certinomis / Docapost: Failure to respond to January 2018 survey |
RESOLVED |
FIXED |
2023-02-22T18:17:50Z |
1439127 |
TurkTrust: Failure to respond to January 2018 survey |
RESOLVED |
FIXED |
2023-02-22T18:13:18Z |
1439128 |
E-Tugra: Failure to respond to January 2018 survey |
RESOLVED |
FIXED |
2023-02-22T18:16:45Z |
1439129 |
DSV-Gruppe: Failure to respond to January 2018 survey |
RESOLVED |
FIXED |
2023-03-20T15:00:54Z |
1442091 |
DigiCert: Unrevocation of BT Class 2 CA - G2 CA Certificate |
RESOLVED |
FIXED |
2023-02-22T18:13:40Z |
1443731 |
SwissSign: Cert issued with a to long validity period |
RESOLVED |
FIXED |
2023-02-22T18:20:51Z |
1443733 |
SwissSign: Cert issued with a to long validity period |
RESOLVED |
DUPLICATE |
2023-02-22T18:28:34Z |
1443857 |
Camerfirma: Non-BR-Compliant Issuance - DNSName is empty |
RESOLVED |
FIXED |
2023-02-22T18:22:19Z |
1444455 |
DocuSign/Keynectis: Non-Compliant Technically Constrained Intermediates |
RESOLVED |
FIXED |
2023-02-22T18:17:19Z |
1445857 |
DigiCert: Mis-issuance of certificate with https in CN/SAN |
RESOLVED |
FIXED |
2023-02-22T18:13:36Z |
1446080 |
Let's Encrypt: Improper encoding of wildcard certificates |
RESOLVED |
FIXED |
2023-02-22T18:18:53Z |
1446121 |
IdenTrust: Improper encoding of wildcard certificate |
RESOLVED |
FIXED |
2023-02-22T18:25:41Z |
1447192 |
DigiCert: Onion Certs |
RESOLVED |
FIXED |
2023-02-22T18:19:19Z |
1447497 |
DocuSign/Keynectis: Outdated audit statements for Class 2 Primary CA |
RESOLVED |
WORKSFORME |
2022-11-14T22:22:57Z |
1448986 |
Entrust: IP Address in dNSName form |
RESOLVED |
FIXED |
2023-02-22T18:14:45Z |
1449371 |
E-Tugra: Validity period > 825 days |
RESOLVED |
FIXED |
2023-02-22T18:16:54Z |
1451228 |
Asseco DS / Certum: EV certificate mis-issue |
RESOLVED |
FIXED |
2023-02-22T18:12:47Z |
1451446 |
DigiCert / ABB: greater than 825 day cert issuance |
RESOLVED |
FIXED |
2023-02-22T18:13:54Z |
1451949 |
Dhimyotis / Certigna: Intermediate Cert(s) not disclosed in CCADB |
RESOLVED |
FIXED |
2023-02-22T18:18:45Z |
1451950 |
DigiCert: Intermediate Cert(s) not disclosed in CCADB |
RESOLVED |
FIXED |
2023-02-22T18:13:35Z |
1451953 |
Telia: Intermediate Cert(s) Not Disclosed in CCADB |
RESOLVED |
FIXED |
2024-05-09T23:39:02Z |
1452671 |
SECOM: TSA Certs Issued from Root |
RESOLVED |
FIXED |
2023-02-22T18:18:29Z |
1455119 |
Firmaprofesional: Undisclosed Intermediate certificate |
RESOLVED |
FIXED |
2023-02-22T18:15:58Z |
1455128 |
Certicamara: Undisclosed Intermediate certificates |
RESOLVED |
FIXED |
2023-02-22T18:28:09Z |
1455132 |
SwissSign: Undisclosed Intermediate Certificates |
RESOLVED |
FIXED |
2023-02-22T18:20:53Z |
1455137 |
T-Systems: Undisclosed Intermediate certificate |
RESOLVED |
FIXED |
2023-02-22T18:13:42Z |
1455147 |
Camerfirma: Missing audit for Intermediate certificate |
RESOLVED |
FIXED |
2023-02-22T18:22:16Z |
1455150 |
DigiCert: Missing audits for Intermediate certificates |
RESOLVED |
FIXED |
2023-02-22T18:13:38Z |
1456655 |
DigiCert / ABB: Issues with DN, country code and keyUsage |
RESOLVED |
FIXED |
2023-02-22T18:13:51Z |
1458038 |
DocuSign/Keynectis: Missing BR Self Assessment |
RESOLVED |
WONTFIX |
2022-11-14T22:22:57Z |
1458042 |
ACCV: Missing BR Self Assessment |
RESOLVED |
FIXED |
2023-02-22T18:19:00Z |
1458064 |
Firmaprofesional: Missing BR Self Assessment |
RESOLVED |
FIXED |
2023-02-22T18:15:56Z |
1459557 |
SwissSign: Certificate issue with Signature |
RESOLVED |
FIXED |
2023-02-22T18:20:52Z |
1461391 |
Comodo: Misissuance using "CNAME CSR Hash 2" method of domain control validation |
RESOLVED |
FIXED |
2023-02-22T18:25:07Z |
1462423 |
NetLock: CN not in SAN |
RESOLVED |
FIXED |
2023-02-22T18:27:50Z |
1462735 |
Let's Encrypt: Case-sensitive CAA tag processing |
RESOLVED |
FIXED |
2023-02-22T18:18:49Z |
1462797 |
E-Tugra: Improper DER results in failure to comply with RFC 5280 - Invalid characters in PrintableString |
RESOLVED |
FIXED |
2023-02-22T18:16:49Z |
1462844 |
GoDaddy: Improper DER results in failure to comply with RFC 5280 - Invalid characters in PrintableString |
RESOLVED |
FIXED |
2023-02-22T18:16:38Z |
1463975 |
GRCA: Misissued certificates: Invalid commonName, commonName not in SAN |
RESOLVED |
FIXED |
2023-02-22T18:18:06Z |
1464286 |
Swisscom: Missing Audits for Unconstrained Intermediate Certificates |
RESOLVED |
FIXED |
2023-02-22T18:18:33Z |
1464335 |
Firmaprofesional: Undisclosed Intermediate certificate SIGNE |
RESOLVED |
FIXED |
2023-02-22T18:28:28Z |
1464359 |
Firmaprofesional: Undisclosed Intermediate certificate SDS |
RESOLVED |
FIXED |
2023-02-22T18:28:27Z |
1465600 |
DigiCert: Invalid Country Code Issuance |
RESOLVED |
FIXED |
2023-02-22T18:14:08Z |
1466252 |
Cybertrust Japan: three test websites not provided |
RESOLVED |
FIXED |
2023-02-22T18:22:26Z |
1467110 |
Consorci AOC: OCSP responding good for non-issued certs by Consorci AOC root already solved |
RESOLVED |
DUPLICATE |
2024-05-09T23:33:19Z |
1467414 |
GDCA: Misissuance of certificates with small RSA keys |
RESOLVED |
FIXED |
2023-02-22T18:15:28Z |
1468000 |
Camerfirma: Invalid country field for Camerfirma root CA certificates |
VERIFIED |
INVALID |
2024-05-09T23:23:42Z |
1468477 |
QuoVadis / Freistaat Bayern: Non-BR-compliant Key Usage |
RESOLVED |
FIXED |
2024-05-09T23:37:23Z |
1472052 |
QuoVadis: Certificate containing Debian weak key |
RESOLVED |
FIXED |
2023-02-22T18:26:25Z |
1473971 |
SwissSign: Domain validated certificate but with stateOrProvinceName |
RESOLVED |
FIXED |
2023-02-22T18:24:46Z |
1475115 |
Telia: Qualified Audit Statements |
RESOLVED |
FIXED |
2023-02-22T18:24:00Z |
1475563 |
GDCA: Misissuance of certificates with IP address |
RESOLVED |
INVALID |
2022-11-14T22:22:57Z |
1478933 |
Camerfirma: Qualified Audit Statements |
RESOLVED |
FIXED |
2023-02-22T18:22:21Z |
1481862 |
Camerfirma: MULTICERT organizationName Too Long |
RESOLVED |
FIXED |
2023-02-22T18:22:18Z |
1483639 |
DigiCert / ADACOM: published expired CRLs |
RESOLVED |
FIXED |
2024-06-30T18:36:07Z |
1483715 |
DigiCert: improper use of domain validation method |
RESOLVED |
FIXED |
2024-06-30T03:28:14Z |
1484766 |
GoDaddy: Random Value Vulnerability in Domain Validation Method |
RESOLVED |
FIXED |
2024-06-30T03:31:10Z |
1485413 |
Certigna: Issuance without respecting CAA records |
RESOLVED |
FIXED |
2023-02-22T18:18:43Z |
1485851 |
Visa: Qualified Audit Statements |
RESOLVED |
FIXED |
2023-02-22T18:24:32Z |
1486650 |
Let's Encrypt: OCSP "unauthorized" responses |
RESOLVED |
FIXED |
2023-02-22T18:18:56Z |
1492006 |
Sectigo: Failure to revoke within 24 hours |
RESOLVED |
FIXED |
2023-02-22T18:25:20Z |
1493760 |
QuoVadis: improper countryName format |
RESOLVED |
FIXED |
2023-02-22T18:26:32Z |
1495497 |
KIR S.A.: Certificates issued with multiple BR violations |
RESOLVED |
FIXED |
2023-02-22T18:24:20Z |
1495507 |
FNMT: OU exceeds 64 characters |
RESOLVED |
FIXED |
2023-02-22T18:24:37Z |
1495518 |
Asseco DS / Certum: Unallowed key usage for EC public key (Key Encipherment) |
RESOLVED |
FIXED |
2023-02-22T18:28:50Z |
1495524 |
Certinomis: Unqualified Domain Name in SAN |
RESOLVED |
FIXED |
2023-02-22T18:22:00Z |
1496088 |
Certinomis: test certificate for test.com, O=Entreprise TEST |
RESOLVED |
FIXED |
2024-06-30T19:16:53Z |
1496616 |
Consorci AOC: Qualified audit statements |
RESOLVED |
FIXED |
2023-02-22T18:17:46Z |
1497700 |
DocuSign/Keynectis: Undisclosed Intermediate certificate |
RESOLVED |
WONTFIX |
2022-11-14T22:22:57Z |
1497703 |
SECOM: Undisclosed intermediate certificates |
RESOLVED |
FIXED |
2023-02-22T18:18:30Z |
1498409 |
Certicamara: Failure to respond to September 2018 CA Survey |
RESOLVED |
FIXED |
2023-03-20T15:01:11Z |
1498463 |
T-Systems: Improperly encoded QCStatements extension |
RESOLVED |
FIXED |
2023-02-22T18:13:41Z |
1499585 |
DigiCert: Undisclosed CAs -Federated Trust CA-1 |
RESOLVED |
FIXED |
2023-02-22T18:28:20Z |
1500593 |
IdenTrust: Internal names / failure to report |
RESOLVED |
FIXED |
2023-02-22T18:25:43Z |
1500621 |
DigiCert: Internal Domain Name cert mis-issuance |
RESOLVED |
FIXED |
2023-02-22T18:14:07Z |
1501374 |
Comodo: CA issuing EV Certs without Higher Authority checks |
RESOLVED |
INVALID |
2024-05-09T21:00:47Z |
1502957 |
Camerfirma: MULTICERT Misissuance and missing audits |
RESOLVED |
FIXED |
2023-02-22T18:22:17Z |
1503128 |
Certinomis: email address in DNS SAN |
RESOLVED |
FIXED |
2023-02-22T18:21:53Z |
1503638 |
WISeKey: Failure to disclose intermediate in CCADB |
RESOLVED |
FIXED |
2023-02-22T18:24:08Z |
1506607 |
SwissSign: Misissuance of Intermediate Certificates because of incorrect organizationIdentifier |
RESOLVED |
FIXED |
2023-02-22T18:22:46Z |
1507862 |
ACCV: Late Audit Statement |
RESOLVED |
FIXED |
2023-02-22T18:18:59Z |
1509002 |
Camerfirma: MULTICERT certificates with a validity period greater than 825 days |
RESOLVED |
FIXED |
2023-02-22T18:17:28Z |
1509512 |
D-TRUST: syntax error in one tls certificate |
RESOLVED |
FIXED |
2023-02-22T18:17:13Z |
1511459 |
Asseco DS / Certum: Corrupted certificates |
RESOLVED |
FIXED |
2023-02-22T18:28:40Z |
1512018 |
Entrust: Certificate issued with '-' in ST field |
RESOLVED |
FIXED |
2023-02-22T18:14:38Z |
1512270 |
Microsec: Validity period greater than 825 days |
RESOLVED |
FIXED |
2023-02-22T18:27:09Z |
1515564 |
DigiCert: Underscore character certificates |
RESOLVED |
DUPLICATE |
2023-02-22T18:19:49Z |
1515788 |
DigiCert: Underscores - CVS Pharmacy |
RESOLVED |
FIXED |
2023-02-22T18:14:19Z |
1516453 |
DigiCert: Underscores - Discover |
RESOLVED |
FIXED |
2023-02-22T18:14:20Z |
1516545 |
DigiCert: Underscores - Verizon |
RESOLVED |
FIXED |
2023-02-22T18:14:24Z |
1516561 |
DigiCert: Underscores - Canadian Imperial Bank of Commerce |
RESOLVED |
FIXED |
2023-02-22T18:14:17Z |
1516599 |
DigiCert: Underscores - Ericsson |
RESOLVED |
FIXED |
2023-02-22T18:14:22Z |
1517617 |
DigiCert: Underscores - Citi |
RESOLVED |
FIXED |
2023-02-22T18:14:18Z |
1518553 |
Sectigo: Use of forbidden subjectPublicKeyInfo algorithm |
RESOLVED |
FIXED |
2023-02-22T18:25:24Z |
1518555 |
DigiCert: Use of forbidden subjectPublicKeyInfo algorithm |
RESOLVED |
FIXED |
2023-02-22T18:19:50Z |
1518560 |
Asseco DS / Certum: Use of forbidden subjectPublicKeyInfo algorithm |
RESOLVED |
FIXED |
2023-02-22T18:28:51Z |
1519260 |
QuoVadis: Multiple unreported misissuances in 2018 |
RESOLVED |
FIXED |
2023-02-22T18:26:38Z |
1519265 |
QuoVadis: Recap of BR Compliance in 2018 issuance by external subCAs |
VERIFIED |
FIXED |
2022-11-14T22:22:57Z |
1519572 |
DigiCert: Underscores - Intuit |
RESOLVED |
FIXED |
2023-02-22T18:14:23Z |
1520299 |
Hongkong Post / Certizen: Failure to report misissuance |
RESOLVED |
FIXED |
2023-02-22T18:21:50Z |
1520876 |
Entrust: Late mis-issue certificate revocation |
RESOLVED |
FIXED |
2023-02-22T18:14:47Z |
1521520 |
Entrust: Late revocation of underscore certificate |
RESOLVED |
FIXED |
2023-02-22T18:14:50Z |
1521623 |
Amazon Trust Services: Failure to comply with RFC 5280 |
RESOLVED |
INVALID |
2024-05-09T20:56:24Z |
1521950 |
QuoVadis: BR Error - san dns name starts with period |
RESOLVED |
FIXED |
2023-02-22T18:26:16Z |
1522080 |
T-Systems: DFN-PKI - Non-IDNA 2003 IDNs, violation of RFC 5280 |
RESOLVED |
INVALID |
2022-11-14T22:22:57Z |
1522975 |
Google Trust Services: Improper OCSP response for intermediate certificate |
RESOLVED |
FIXED |
2023-02-22T18:21:05Z |
1523186 |
KIR S.A.: Misissuance - missing OCSP AIA, Validity > 825 days |
RESOLVED |
FIXED |
2023-02-22T18:24:29Z |
1523221 |
GRCA: Misissued certificates - invalid CN, bad validity period, missing extensions |
RESOLVED |
FIXED |
2023-02-22T18:18:05Z |
1523676 |
DigiCert: Good OCSP Responses for Revoked Intermediates |
RESOLVED |
FIXED |
2023-02-22T18:13:34Z |
1523680 |
Actalis: Non BR Compliant OCSP Responder |
RESOLVED |
FIXED |
2023-02-22T18:12:01Z |
1524050 |
Telia: Misissued certificate - invalid dnsName |
RESOLVED |
FIXED |
2023-02-22T18:23:55Z |
1524094 |
Certinomis: invalid DNS names in SAN |
RESOLVED |
FIXED |
2023-02-22T18:21:55Z |
1524103 |
Certinomis: invalid state and locality fields in subject |
RESOLVED |
FIXED |
2023-02-22T18:21:57Z |
1524112 |
Certinomis: test certificates, O=POUR TEST in subject |
RESOLVED |
FIXED |
2024-06-30T19:17:57Z |
1524143 |
CFCA: Internal iPAddress in certificate |
RESOLVED |
FIXED |
2023-02-22T18:20:31Z |
1524195 |
Asseco DS / Certum: Invalid dnsNames |
RESOLVED |
FIXED |
2023-02-22T18:28:45Z |
1524448 |
Certinomis: misissued test certificates |
RESOLVED |
FIXED |
2024-06-30T19:17:15Z |
1524449 |
Certinomis: validity period >825 days |
RESOLVED |
FIXED |
2023-02-22T18:22:01Z |
1524451 |
Certinomis: invalid CDP extension |
RESOLVED |
FIXED |
2023-02-22T18:21:54Z |
1524452 |
SECOM: certificate for .test TLD |
RESOLVED |
FIXED |
2023-02-22T18:18:12Z |
1524567 |
Telia: invalid IP value in SAN DNS field |
RESOLVED |
FIXED |
2023-02-22T18:23:52Z |
1524730 |
Sectigo: invalid dnsName |
RESOLVED |
FIXED |
2023-02-22T18:25:21Z |
1524733 |
CFCA: invalid dnsNames |
RESOLVED |
FIXED |
2023-02-22T18:20:33Z |
1524815 |
GoDaddy: failure to revoke underscores |
RESOLVED |
FIXED |
2023-02-22T18:20:02Z |
1524816 |
SECOM: failure to revoke underscores |
RESOLVED |
FIXED |
2023-02-22T18:18:21Z |
1524871 |
Camerfirma: failure to revoke underscores |
RESOLVED |
FIXED |
2023-02-22T18:17:23Z |
1524875 |
DigiCert: IP in dnsName |
RESOLVED |
FIXED |
2023-02-22T18:14:11Z |
1524876 |
Entrust: IP in dnsName |
RESOLVED |
FIXED |
2023-02-22T18:14:46Z |
1524877 |
GlobalSign: IP in dnsName |
RESOLVED |
FIXED |
2023-02-22T18:16:30Z |
1524878 |
Asseco DS / Certum: IP in dnsName |
RESOLVED |
DUPLICATE |
2023-02-22T18:28:47Z |
1524879 |
QuoVadis: IP in dnsName |
RESOLVED |
FIXED |
2023-02-22T18:26:36Z |
1525710 |
Amazon Trust Services: Test revoked certificates with invalid validity period |
RESOLVED |
FIXED |
2023-02-22T18:27:42Z |
1526099 |
IdenTrust: Discrepancy in values of address fields within CN of SSL Certificates |
RESOLVED |
FIXED |
2023-02-22T18:25:35Z |
1526154 |
DigiCert: Missed Underscore Certificate Revocations |
RESOLVED |
FIXED |
2023-02-22T18:14:13Z |
1527423 |
DigiCert: P-384,ecdsa-with-SHA512 Certificates |
RESOLVED |
FIXED |
2023-02-22T18:14:15Z |
1528259 |
Telia: misissued certificate - FQDN value incorrectly in SAN rfc822 field |
RESOLVED |
FIXED |
2023-02-22T18:23:53Z |
1528261 |
Telia: Misissued certificate - FQDN without domain part (e_dnsname_not_valid_tld) |
RESOLVED |
FIXED |
2023-02-22T18:23:54Z |
1528263 |
Telia: Misissued certificate - Invalid wildcard format |
RESOLVED |
FIXED |
2023-02-22T18:23:57Z |
1528264 |
Telia: Misissued certificate - Invalid OU value "-" |
RESOLVED |
FIXED |
2023-02-22T18:23:56Z |
1528290 |
Izenpe: OU > 64 characters |
RESOLVED |
FIXED |
2023-02-22T18:23:33Z |
1530623 |
QuoVadis: IPaddress in DNSname SAN |
RESOLVED |
FIXED |
2023-02-22T18:26:20Z |
1530718 |
T-Systems: Invalid SAN Entries |
RESOLVED |
FIXED |
2023-02-22T18:12:55Z |
1530971 |
HARICA: P-384,ecdsa-with-SHA256 Certificates |
RESOLVED |
FIXED |
2023-02-22T18:20:13Z |
1531800 |
QuoVadis: DarkMatter Insufficient Serial Number Entropy |
RESOLVED |
FIXED |
2023-02-22T18:26:07Z |
1531817 |
DigiCert: in-addr.arpa Misissuance |
RESOLVED |
FIXED |
2023-02-22T18:19:32Z |
1532105 |
SECOM: CrossTrust: OU > 64 characters |
RESOLVED |
FIXED |
2023-02-22T18:18:16Z |
1532112 |
KIR S.A.: O > 64 characters |
RESOLVED |
DUPLICATE |
2023-02-22T18:24:30Z |
1532113 |
CFCA: O > 64 characters |
RESOLVED |
FIXED |
2023-02-22T18:26:47Z |
1532313 |
Comodo: Possible CAA Misissuance due against critical record |
RESOLVED |
INVALID |
2022-11-14T22:22:57Z |
1532333 |
Camerfirma: Unrevocation of MULTICERT SSL Certification Authority 001 certificate |
RESOLVED |
FIXED |
2023-02-22T18:17:31Z |
1532399 |
TrustCor: Insufficient Serial Number Entropy |
RESOLVED |
FIXED |
2023-02-22T18:23:13Z |
1532429 |
CFCA: Invalid TLD in SAN |
RESOLVED |
FIXED |
2023-02-22T18:20:34Z |
1532436 |
Chunghwa Telecom: Test certificate with unregistered domain name |
RESOLVED |
FIXED |
2023-02-22T18:24:43Z |
1532559 |
CFCA: Wrong SerialNumber encoding |
RESOLVED |
FIXED |
2023-02-22T18:20:35Z |
1532842 |
Google Trust Services: 63 bit serial numbers in some certificates |
RESOLVED |
FIXED |
2023-02-22T18:26:05Z |
1533655 |
DigiCert: Apple: Non-compliant Serial Numbers |
RESOLVED |
FIXED |
2023-02-22T18:15:46Z |
1533774 |
GoDaddy: Insufficient serial number entropy |
RESOLVED |
FIXED |
2023-02-22T18:20:04Z |
1533899 |
Quovadis: Insufficient Serial Number Entropy |
RESOLVED |
INVALID |
2022-11-14T22:22:57Z |
1534145 |
SSL.com: P-384 curve / ecdsa-with-SHA256 certificates |
RESOLVED |
FIXED |
2023-02-22T18:22:31Z |
1534147 |
SSL.com: Insufficient serial number entropy |
RESOLVED |
FIXED |
2023-02-22T18:22:30Z |
1534295 |
Actalis: Insufficient serial number entropy |
RESOLVED |
FIXED |
2023-02-22T18:11:58Z |
1534429 |
Camerfirma: Multicert SSL CA 001: Insufficient serial number entropy |
RESOLVED |
FIXED |
2023-02-22T18:15:12Z |
1534535 |
QuoVadis / Siemens: Insufficient serial number entropy |
RESOLVED |
FIXED |
2023-02-22T18:26:04Z |
1534580 |
T-Systems / DFN-PKI: 40 OV certificates with wrong ST |
RESOLVED |
FIXED |
2023-02-22T18:13:48Z |
1535509 |
HARICA: Insufficient serial number entropy |
RESOLVED |
FIXED |
2023-02-22T18:20:11Z |
1535735 |
Entrust: Issued Certificates to incorrect Organization |
RESOLVED |
FIXED |
2023-02-22T18:16:20Z |
1535772 |
HARICA: wrong characters in NC extension of Technically Constrained Intermediate CA Certificates |
RESOLVED |
FIXED |
2023-02-22T18:20:14Z |
1535869 |
Taiwan-CA: Invalid SAN Entries |
RESOLVED |
FIXED |
2023-02-22T18:18:35Z |
1535871 |
PKIoverheid: KPN Insufficient Serial Number Entropy |
RESOLVED |
FIXED |
2023-02-22T18:20:18Z |
1535873 |
GlobalSign: AT&T Insufficient Serial Number Entropy |
RESOLVED |
FIXED |
2023-02-22T18:16:26Z |
1536082 |
T-Systems: Insufficient serial number entropy |
RESOLVED |
FIXED |
2023-02-22T18:12:54Z |
1536213 |
ACCV: Insufficient serial number entropy |
RESOLVED |
FIXED |
2023-02-22T18:18:58Z |
1536287 |
Entrust: AffirmTrust Issuing CA Impacted by EJBCA Serial Number Issue |
RESOLVED |
FIXED |
2023-02-22T18:16:11Z |
1536760 |
GlobalSign: Virginia Tech Insufficient Serial Number Entropy |
RESOLVED |
FIXED |
2023-02-22T18:16:36Z |
1536831 |
GDCA: Insufficient Serial Number Entropy |
RESOLVED |
FIXED |
2023-02-22T18:15:27Z |
1538638 |
Firmaprofesional: AC Firmaprofesional - INFRAESTRUCTURA insufficient serial number entropy |
RESOLVED |
FIXED |
2023-02-22T18:15:53Z |
1538673 |
Consorci AOC: EC-SECTORPUBLIC insufficient serial number entropy |
RESOLVED |
FIXED |
2023-02-22T18:17:41Z |
1539190 |
Kamu SM: Insufficient Serial Number Entropy |
RESOLVED |
FIXED |
2023-02-22T18:22:54Z |
1539296 |
DigiCert: KPN Outdated Audit |
RESOLVED |
FIXED |
2024-06-30T19:43:42Z |
1539307 |
Buypass: Insufficient Serial Number Entropy |
RESOLVED |
FIXED |
2023-02-22T18:21:44Z |
1539358 |
SECOM: Insufficient Serial Number Entropy |
RESOLVED |
FIXED |
2023-02-22T18:18:24Z |
1539531 |
Certinomis: certificates with space in dNSName SAN |
RESOLVED |
FIXED |
2023-02-22T18:21:52Z |
1540281 |
WISeKey: Insufficient Serial Number Entropy |
RESOLVED |
FIXED |
2023-02-22T18:24:13Z |
1540315 |
QuoVadis: LLB insufficient Serial Number Entropy |
RESOLVED |
FIXED |
2023-02-22T18:26:21Z |
1540961 |
Atos: Insufficient Serial Number Entropy |
RESOLVED |
FIXED |
2023-02-22T18:27:45Z |
1541064 |
SwissSign: Error in OrganisationIdentifier in signature/seal certificate |
RESOLVED |
FIXED |
2023-02-22T18:22:40Z |
1542082 |
IdenTrust: Failure to disclose Unconstrained intermediate Within 7 Days |
RESOLVED |
FIXED |
2023-02-22T18:25:38Z |
1542302 |
E-Tugra: Insufficient serial number entropy |
RESOLVED |
FIXED |
2023-02-22T18:16:50Z |
1542328 |
Certinomis: Invalid TLD in SAN |
RESOLVED |
FIXED |
2023-02-22T18:17:57Z |
1542793 |
Certinomis: Invalid SAN in a certificate |
RESOLVED |
FIXED |
2023-02-22T18:17:56Z |
1544586 |
FNMT: Findings in 2019 Audit Statement, including domain validation methods, CAA, etc. |
RESOLVED |
FIXED |
2023-02-22T18:12:11Z |
1544712 |
SECOM: certificate for which “OU=-” |
RESOLVED |
FIXED |
2023-02-22T18:18:14Z |
1544722 |
SECOM: certificate for which “L” and “ST” not set |
RESOLVED |
FIXED |
2023-02-22T18:18:13Z |
1544933 |
Certinomis: certificates for an unregistered domain, with unknown OCSP status |
RESOLVED |
FIXED |
2023-02-22T18:17:53Z |
1545208 |
Sectigo: Missing Changelog in CPS |
RESOLVED |
FIXED |
2023-02-22T18:25:23Z |
1546253 |
GDCA: Authentication of Organization Identity Failure for an OV Certificate |
RESOLVED |
FIXED |
2023-02-22T18:15:25Z |
1546776 |
SecureTrust: Unvalidated domain in certificate |
RESOLVED |
FIXED |
2023-02-22T18:17:37Z |
1547072 |
Certinomis: Use of Domain Validation Method 3.2.2.4.5 after August 1, 2018 |
RESOLVED |
INVALID |
2022-11-14T22:22:57Z |
1547691 |
GlobalSign: AT&T SSL certificates without the AIA extension |
RESOLVED |
FIXED |
2023-02-22T18:16:27Z |
1548713 |
Sectigo: "Default City" in Subject:localityName |
RESOLVED |
FIXED |
2023-02-22T18:25:09Z |
1548714 |
SECOM: "Default City" in Subject:localityName |
RESOLVED |
FIXED |
2023-02-22T18:18:09Z |
1548716 |
DigiCert: Verizon: "Default City" in Subject:localityName |
RESOLVED |
FIXED |
2023-02-22T18:14:25Z |
1548719 |
DigiCert: Revoked intermediate certificates not in CRL |
RESOLVED |
FIXED |
2023-02-22T18:26:12Z |
1548720 |
SSL.com: CRL not found - SSL.com-Enterprise-Intermediate-EV-RSA-4096-R1.crl |
RESOLVED |
FIXED |
2023-02-22T18:26:50Z |
1549308 |
WISeKey: Revocation of multiple intermediate CAs |
RESOLVED |
INVALID |
2022-11-14T22:22:57Z |
1549861 |
Camerfirma: Outdated audit statements for intermediate certs |
RESOLVED |
FIXED |
2023-02-22T18:17:30Z |
1549862 |
Entrust: Outdated audit statement for intermediate cert |
RESOLVED |
FIXED |
2023-02-22T18:14:52Z |
1550547 |
IP certificate issued with Domain Validation |
RESOLVED |
INVALID |
2022-11-14T22:22:57Z |
1550575 |
Asseco DS / Certum: commonName not from subjectAltName entries |
RESOLVED |
FIXED |
2023-02-22T18:28:39Z |
1550576 |
SSL.com: Expired CRLs |
RESOLVED |
INVALID |
2022-11-14T22:22:57Z |
1550645 |
DigiCert: CAA Checking Issue |
RESOLVED |
FIXED |
2023-02-22T18:13:55Z |
1551357 |
Certinomis: certificates with invalid DNS SAN |
RESOLVED |
FIXED |
2023-02-22T18:17:55Z |
1551362 |
Sectigo: "Some-State" in stateOrProvinceName |
RESOLVED |
FIXED |
2023-02-22T18:25:10Z |
1551363 |
DigiCert: "Some-State" in stateOrProvinceName |
RESOLVED |
FIXED |
2023-02-22T18:13:53Z |
1551364 |
SwissSign: "Some-State" in stateOrProvinceName |
RESOLVED |
FIXED |
2023-02-22T18:27:32Z |
1551369 |
Kamu SM: "Some-State" in stateOrProvinceName |
RESOLVED |
FIXED |
2023-02-22T18:22:53Z |
1551371 |
T-Systems: "Some-State" in stateOrProvinceName |
RESOLVED |
FIXED |
2023-02-22T18:12:52Z |
1551372 |
Telia: "Some-State" in stateOrProvinceName |
RESOLVED |
FIXED |
2023-02-22T18:23:49Z |
1551374 |
SecureTrust: "Some-State" in stateOrProvinceName |
RESOLVED |
FIXED |
2023-02-22T18:17:38Z |
1551375 |
certSIGN: "Some-State" in stateOrProvinceName |
RESOLVED |
FIXED |
2023-02-22T18:16:06Z |
1551390 |
Certinomis: 174 certificates with unknown OCSP status |
RESOLVED |
FIXED |
2023-02-22T18:17:52Z |
1552562 |
Entrust: Question marks in certificate O and L fields |
RESOLVED |
FIXED |
2023-02-22T18:14:54Z |
1552586 |
GlobalSign: 4 Misissued certificates with invalid CN |
RESOLVED |
FIXED |
2023-02-22T18:16:25Z |
1554259 |
GlobalSign: SPKI lacks explicit NULL parameter, |
RESOLVED |
FIXED |
2023-02-22T18:16:34Z |
1556806 |
Camerfirma: Infocert misissued certificates |
RESOLVED |
FIXED |
2023-02-22T18:17:26Z |
1556906 |
DigiCert: Apple: Non-compliant Common Name Length |
RESOLVED |
FIXED |
2023-02-22T18:15:45Z |
1556948 |
DigiCert: Validation Scope Incident |
RESOLVED |
FIXED |
2023-02-22T18:19:20Z |
1557085 |
Camerfirma: Intesa Sanpaolo misissued certificates |
RESOLVED |
FIXED |
2023-02-22T18:17:27Z |
1558552 |
SwissSign: CP/CPS certificate profile issue |
RESOLVED |
FIXED |
2023-02-22T18:22:35Z |
1559376 |
Entrust: Certificate Issued with Incorrect Country Code |
RESOLVED |
FIXED |
2023-02-22T18:16:12Z |
1559765 |
Izenpe: Multiple invalid EV certificates issued |
RESOLVED |
FIXED |
2023-02-22T18:23:29Z |
1560234 |
SECOM: Ambiguity on KeyUsage with ECC public key |
RESOLVED |
INVALID |
2022-11-14T22:22:57Z |
1561013 |
Entrust: Certificate issued with validity greater than 825-days |
RESOLVED |
FIXED |
2023-02-22T18:14:39Z |
1563573 |
DigiCert: Failure to disclose Unconstrained Intermediate within 7 Days |
RESOLVED |
FIXED |
2023-02-22T18:13:57Z |
1563574 |
SECOM: Failure to disclose Unconstrained Intermediate within 7 Days |
RESOLVED |
FIXED |
2023-02-22T18:18:19Z |
1563575 |
Telia: Failure to disclose Unconstrained Intermediate within 7 Days |
RESOLVED |
FIXED |
2023-02-22T18:23:51Z |
1563579 |
Sectigo: Failure to provide timely incident reports |
RESOLVED |
FIXED |
2023-02-22T18:25:01Z |
1563772 |
D-TRUST: Precertificate OU > 64 Characters |
RESOLVED |
FIXED |
2023-02-22T18:17:11Z |
1563917 |
QuoVadis: use of Organisationidentifier field in EV (Pre CABF Ballot SC17) |
RESOLVED |
FIXED |
2023-02-22T18:26:41Z |
1565270 |
Telia: Qualified BR Audit Statement |
RESOLVED |
FIXED |
2023-02-22T18:24:01Z |
1565494 |
CFCA: Missed annual CPS update publication on website in 2018 |
RESOLVED |
FIXED |
2024-06-30T20:36:41Z |
1566162 |
DigiCert: Failure to supervise ABB Subordinate CA |
RESOLVED |
FIXED |
2023-02-22T18:19:30Z |
1566580 |
LuxTrust: Overdue Audit Statements 2019 |
RESOLVED |
WORKSFORME |
2022-11-14T22:22:57Z |
1566586 |
Asseco DS / Certum: Overdue Audit Statements 2019 |
RESOLVED |
FIXED |
2023-02-22T18:28:49Z |
1567060 |
Sectigo / Web.com: inconsistent disclosure of externally-operated intermediate |
RESOLVED |
FIXED |
2023-02-22T18:25:08Z |
1567061 |
GoDaddy: inconsistent disclosure of externally-operated intermediate |
RESOLVED |
FIXED |
2023-02-22T18:20:03Z |
1567062 |
Asseco DS / Certum: inconsistent disclosure of externally-operated intermediate |
RESOLVED |
FIXED |
2023-02-22T18:28:43Z |
1567456 |
T-Systems: "Some-State" comparable issues |
RESOLVED |
FIXED |
2023-02-22T18:12:51Z |
1567588 |
D-TRUST: incorrectly formatted businessCategory entry |
RESOLVED |
FIXED |
2023-02-22T18:17:08Z |
1567659 |
Entrust: SHA-1 Issuance and other misissuance while testing |
RESOLVED |
FIXED |
2023-02-22T18:14:56Z |
1568356 |
TrustCor: Incorrect CA-Issuers URI |
RESOLVED |
FIXED |
2023-02-22T18:23:12Z |
1569266 |
Amazon Trust Services: No Space In Private Organization |
RESOLVED |
FIXED |
2023-02-22T18:16:24Z |
1569651 |
SwissSign: Misissuance of Leaf Certificates because of incorrect postcode |
RESOLVED |
FIXED |
2023-02-22T18:27:33Z |
1572234 |
GoDaddy: cross certificate disclosure to CCADB |
RESOLVED |
FIXED |
2023-02-22T18:19:58Z |
1572638 |
Actalis: Failure to revoke certs within the BR required timeframe |
RESOLVED |
FIXED |
2023-02-22T18:18:02Z |
1572992 |
NetLock: Failure to provide regular and timely incident updates |
RESOLVED |
FIXED |
2023-02-22T18:27:53Z |
1573490 |
PKIoverheid: CIBG insufficient serial number entropy |
RESOLVED |
FIXED |
2023-02-22T18:20:36Z |
1573937 |
DigiCert / Verizon: Qualified 2019 Audit Statements |
RESOLVED |
FIXED |
2023-02-22T18:14:27Z |
1574594 |
Amazon Trust Services: Revoked Sample Certs - No SANs |
RESOLVED |
FIXED |
2023-02-22T18:27:41Z |
1575022 |
Sectigo: EV SSL Certificates with incorrect subject details. |
RESOLVED |
FIXED |
2023-02-22T18:25:15Z |
1575125 |
DigiCert: Apple: Unconstrained intermediate CAs not included in WTBR report |
RESOLVED |
FIXED |
2024-06-30T20:05:52Z |
1575530 |
Camerfirma: Govern d'Andorra audits |
RESOLVED |
FIXED |
2023-02-22T18:22:14Z |
1575880 |
GlobalSign: SSL Certificates with US country code and invalid State/Prov |
RESOLVED |
FIXED |
2023-02-22T18:16:35Z |
1576013 |
DigiCert: JOI Issue |
RESOLVED |
FIXED |
2023-02-22T18:19:36Z |
1576133 |
SECOM: Mis-issued EV Certificates |
RESOLVED |
FIXED |
2023-02-22T18:28:52Z |
1576283 |
QuoVadis: N/A in EV serialNumber field |
RESOLVED |
FIXED |
2023-02-22T18:26:22Z |
1576789 |
Let's Encrypt: 2019.08.20 Incident: Incorrect OCSP responses under certain conditions |
RESOLVED |
FIXED |
2024-05-09T23:25:12Z |
1577014 |
DigiCert: OCSP services returns 1 byte |
RESOLVED |
FIXED |
2023-02-22T18:19:18Z |
1577652 |
Let's Encrypt: OCSP Responder Returned "Unauthorized" for Some Precertificates |
RESOLVED |
INVALID |
2022-11-14T22:22:57Z |
1577913 |
GoDaddy: Issues with State and Country fields |
RESOLVED |
FIXED |
2023-02-22T18:20:05Z |
1578417 |
T-Systems: Issue with Organization field |
RESOLVED |
FIXED |
2023-02-22T18:12:56Z |
1578505 |
LuxTrust: Outdated audit statement for intermediate certificate |
RESOLVED |
FIXED |
2024-06-30T20:09:07Z |
1578809 |
PKIoverheid: Compliance issues CIBG TLS certificates |
RESOLVED |
FIXED |
2023-02-22T18:20:17Z |
1579284 |
TrustCor: Non-audited intermediate certificates |
RESOLVED |
FIXED |
2023-02-22T18:23:14Z |
1579299 |
Asseco DS / Certum: non-audited intermediate certificate |
RESOLVED |
INVALID |
2023-02-22T18:12:14Z |
1579413 |
GlobalSign: OCSP Responder Returns invalid values for Some Precertificates |
RESOLVED |
INVALID |
2022-11-14T22:22:57Z |
1579509 |
SSL.com: Precertificates without corresponding certificates return OCSP value of "Unknown" |
RESOLVED |
INVALID |
2022-11-14T22:22:57Z |
1579950 |
QuoVadis: OCSP handling of Certificate Transparency Pre-certs |
RESOLVED |
INVALID |
2022-11-14T22:22:57Z |
1580393 |
HARICA: OCSP Responder Returned "Unauthorized" for Some Precertificates |
RESOLVED |
INVALID |
2022-11-14T22:22:57Z |
1580525 |
D-TRUST: Delayed revocation of EV certificates |
RESOLVED |
FIXED |
2023-02-22T18:17:06Z |
1581183 |
Google Trust Services: CRL handling of expired certificates not fully compliant with RFC 5280 Section 3.3 |
RESOLVED |
FIXED |
2023-02-22T18:13:20Z |
1581234 |
QuoVadis: EV JOI Issue |
RESOLVED |
FIXED |
2023-02-22T18:26:26Z |
1581597 |
QuoVadis: Unconstrained CAs missing audits |
RESOLVED |
FIXED |
2023-02-22T18:26:24Z |
1582519 |
DigiCert: Apple: Precertificates without corresponding certificates return OCSP value of "unknown" |
RESOLVED |
INVALID |
2022-11-14T22:22:57Z |
1582601 |
E-Tugra: Invalid DER results in failure to comply with RFC 5280 - Violating string length limit |
RESOLVED |
FIXED |
2023-02-22T18:16:52Z |
1583470 |
Camerfirma: audit gap |
RESOLVED |
FIXED |
2023-02-22T18:12:22Z |
1586115 |
Firmaprofesional / SIGNE: No BR Audit for intermediate CA technically capable of issuing TLS certs |
RESOLVED |
FIXED |
2024-06-30T20:07:43Z |
1586125 |
PKIoverheid: No BR Audit for Intermediate CAs technically capable of issuing TLS certs |
RESOLVED |
FIXED |
2024-06-30T20:11:37Z |
1586604 |
DigiCert: TERENA: No localityName in EV precert |
RESOLVED |
INVALID |
2022-11-14T22:22:57Z |
1586787 |
Actalis: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy |
RESOLVED |
FIXED |
2023-02-22T18:18:03Z |
1586792 |
QuoVadis: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy or the BRs |
RESOLVED |
FIXED |
2023-02-22T18:26:37Z |
1586795 |
NetLock: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy |
RESOLVED |
FIXED |
2023-02-22T18:27:55Z |
1586847 |
Microsoft PKI Services: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy |
RESOLVED |
FIXED |
2024-05-09T23:27:52Z |
1586860 |
Camerfirma: Invalid authorityKeyIdentifier, violating Mozilla Policy and RFC 5280 |
RESOLVED |
FIXED |
2023-02-22T18:22:15Z |
1588001 |
Apple: OCSP responders return responses with incorrect issuer |
RESOLVED |
FIXED |
2023-02-22T18:15:42Z |
1588213 |
IdenTrust: Missing Thumbprints for Intermediate CA certificates In Some Annual Audit Reports |
RESOLVED |
FIXED |
2024-06-30T20:08:31Z |
1589047 |
QuoVadis: Incorrect EV jurisdiction of incorporation information |
RESOLVED |
FIXED |
2023-02-22T18:26:33Z |
1590171 |
QuoVadis: failure to reply to CPR in a timely manner |
RESOLVED |
FIXED |
2024-06-30T20:25:51Z |
1590723 |
Consorci AOC: Misissued certificates: commonName:organizationIdentifier attribute inclusion not conforming CABForum guidelines 1.6.9 |
RESOLVED |
FIXED |
2024-05-09T21:00:57Z |
1590810 |
Sectigo: EV SSL Certificates with incorrect businessCategory |
RESOLVED |
FIXED |
2023-02-22T18:25:14Z |
1591005 |
GlobalSign: ICAs in CCADB, without EKU extension are listed in WTCA report but not in WTBR report |
RESOLVED |
FIXED |
2023-02-22T18:13:11Z |
1593357 |
QuoVadis: Incorrect EV businessCategory |
RESOLVED |
FIXED |
2023-02-22T18:26:19Z |
1593776 |
Sectigo: invalid subject:organizationalUnitName on DV certificates |
RESOLVED |
FIXED |
2023-02-22T18:25:22Z |
1593814 |
DigiCert: & character in a printableString in ICA |
RESOLVED |
FIXED |
2023-02-22T18:19:21Z |
1595113 |
Buypass: Intermediate certificates not listed in audit reports |
RESOLVED |
FIXED |
2023-02-22T18:21:45Z |
1595921 |
DigiCert: Domain validation skipped |
RESOLVED |
FIXED |
2023-02-22T18:19:25Z |
1596744 |
Izenpe: Intermediate CA certificates not listed in audit report |
RESOLVED |
FIXED |
2024-06-30T20:08:48Z |
1596923 |
PKIoverheid: KPN CPS lacks CPR problem reporting instructions |
RESOLVED |
FIXED |
2024-06-30T20:25:19Z |
1596931 |
DigiCert: Verizon CPS lacks CPR problem reporting instructions |
RESOLVED |
FIXED |
2024-06-30T20:22:39Z |
1596949 |
FNMT: CP/CPS lack CAA processing details |
RESOLVED |
FIXED |
2023-02-22T18:12:10Z |
1597135 |
HARICA: 3 EV TLS Certificates without L or ST |
RESOLVED |
FIXED |
2023-02-22T18:20:07Z |
1597947 |
Sectigo: CCADB failed ALV - Network Solutions Certificate Authority |
RESOLVED |
FIXED |
2023-02-22T18:24:58Z |
1597948 |
Sectigo: Missing Intermediate CA Certificate in Audit - D-TRUST CA 2-1 2015 |
RESOLVED |
FIXED |
2024-06-30T20:13:47Z |
1597950 |
Sectigo: CCADB failed ALV - Ensured Root CA |
RESOLVED |
FIXED |
2023-02-22T18:25:13Z |
1598277 |
Asseco DS / Certum: Intermediate CA certificates not listed in audit report |
RESOLVED |
FIXED |
2024-06-30T20:04:30Z |
1598319 |
Buypass: intermediate certificates not revoked within BR time period |
RESOLVED |
FIXED |
2023-02-22T18:21:46Z |
1598390 |
Microsoft PKI Services: Null Character Bug and Microsoft Root CAs |
RESOLVED |
FIXED |
2024-05-09T23:27:53Z |
1598608 |
Izenpe: intermediate certificates not revoked within BR time period |
RESOLVED |
FIXED |
2023-02-22T18:23:28Z |
1598807 |
IdenTrust: Undisclosed Unrevoked ICAs |
RESOLVED |
FIXED |
2023-02-22T18:26:00Z |
1598829 |
Apple: Patch Management |
RESOLVED |
FIXED |
2023-02-22T18:15:43Z |
1599484 |
Entrust: EV Certificates Issued with Business Category "Non-Commercial" when it should have been set to "Private Organization" |
RESOLVED |
FIXED |
2023-02-22T18:16:14Z |
1599503 |
TrustCor: No mention of TLS-capable Intermediate CAs in WTBR audit reports |
RESOLVED |
FIXED |
2024-06-30T20:17:34Z |
1599561 |
D-TRUST: EV certificates with incorrectly used businessCategory entry |
RESOLVED |
FIXED |
2023-02-22T18:17:07Z |
1599571 |
TrustCor: Non-revocation of CA certificates within 7 days |
RESOLVED |
FIXED |
2023-02-22T18:23:16Z |
1599775 |
GlobalSign: Wrong business category (Non Commercial Entity when should have been Private Organization) |
RESOLVED |
FIXED |
2023-02-22T18:17:32Z |
1599788 |
GlobalSign: Failure to revoke noncompliant ICA within 7 days |
RESOLVED |
FIXED |
2023-02-22T18:13:09Z |
1599916 |
QuoVadis: Unconstrained CAs revocation |
RESOLVED |
FIXED |
2023-02-22T18:26:40Z |
1600114 |
Camerfirma: EV Certificates issued with wrong Business Category |
RESOLVED |
FIXED |
2023-02-22T18:12:30Z |
1600158 |
Asseco DS / Certum: Failure to revoke intermediate certificates within the BR time period |
RESOLVED |
FIXED |
2023-02-22T18:28:42Z |
1600301 |
Asseco DS / Certum: EV Certificates issued with wrong Business Category |
RESOLVED |
FIXED |
2023-02-22T18:12:13Z |
1600844 |
SecureTrust: Unconstrained Intermediate CA Certificate not included in WTBR audit report |
RESOLVED |
FIXED |
2024-06-30T20:16:09Z |
1602999 |
Microsoft PKI Services: Loss of Archived Firewall logs from Retention Store |
RESOLVED |
FIXED |
2024-05-09T23:27:54Z |
1604124 |
Microsoft DSRE PKI: problem reporting e-mail in CPS does not work |
RESOLVED |
FIXED |
2023-02-22T18:16:56Z |
1605126 |
PKIoverheid: Missing intermediate CA certificates in WTBR audit statements Staat der Nederlanden 2017/2018 |
RESOLVED |
FIXED |
2024-06-30T20:11:17Z |
1605372 |
GlobalSign: OCSP responders found to respond signed by the default CA when passed an invalid issuer in request |
RESOLVED |
FIXED |
2023-02-22T18:16:33Z |
1605804 |
GoDaddy: Domain Validation Reuse Issue |
RESOLVED |
FIXED |
2023-02-22T18:19:59Z |
1606031 |
SecureTrust: BR Audit 2019 - matters to be resolved |
RESOLVED |
FIXED |
2023-02-22T18:15:30Z |
1606380 |
Firmaprofesional: 2019 Audit Report Findings |
RESOLVED |
FIXED |
2023-02-22T18:15:51Z |
1608333 |
CFCA: Wrong OrganizationName |
RESOLVED |
FIXED |
2023-02-22T18:26:50Z |
1609501 |
WISeKey: Typo in Organization field |
RESOLVED |
FIXED |
2023-02-22T18:24:17Z |
1609706 |
PKIoverheid: Missing Intermediate CA from audit statement |
RESOLVED |
FIXED |
2024-06-30T20:10:26Z |
1609828 |
Camerfirma: Decision not to revoke certificates with authorityKeyIdentifier that violates Mozilla Policy |
RESOLVED |
FIXED |
2023-02-22T18:22:11Z |
1610000 |
SSL.com: Intermediate certificate not listed in audit reports |
RESOLVED |
FIXED |
2023-02-22T18:26:55Z |
1610303 |
D-TRUST: Issuance of non-conformant SSL certificate |
RESOLVED |
FIXED |
2023-02-22T18:17:10Z |
1610448 |
Firmaprofesional: 2019 audit Finding #1 - 6.2 Identification and Authorization |
RESOLVED |
FIXED |
2023-02-22T18:15:49Z |
1610507 |
PKIoverheid: TSP CPS lacks problem reporting instructions |
RESOLVED |
DUPLICATE |
2023-02-22T18:20:46Z |
1610767 |
WISeKey: Failure to meet revocation deadline |
RESOLVED |
FIXED |
2023-02-22T18:24:10Z |
1611241 |
Entrust: Compromised Private Key was not Revoked in Less than 24 Hours |
RESOLVED |
FIXED |
2023-02-22T18:16:13Z |
1611458 |
Asseco DS / Certum: Invalid value in SAN dNSName |
RESOLVED |
FIXED |
2023-02-22T18:28:46Z |
1612332 |
Telia: Ambiguity on KeyUsage with ECC public key |
RESOLVED |
FIXED |
2023-02-22T18:23:44Z |
1612389 |
Google Trust Services: invalid curve-hash combination |
RESOLVED |
FIXED |
2023-02-22T18:13:27Z |
1612929 |
Firmaprofesional: 2019 audit Finding #2 - 6.4 Facility, management, and operational controls |
RESOLVED |
FIXED |
2023-02-22T18:15:50Z |
1613334 |
SwissSign: Misissuance with mispellings in Location for a number of Certificates |
RESOLVED |
FIXED |
2023-02-22T18:22:47Z |
1613406 |
SwissSign: Delayed revocation for mispellings in Location for a number of Certificates |
RESOLVED |
FIXED |
2023-02-22T18:22:36Z |
1613409 |
CFCA: Repeated unexplained delays in providing timely status updates |
RESOLVED |
FIXED |
2023-02-22T18:26:49Z |
1613505 |
DigiCert: WTCA / WTBR Audit 2019 - Matters to be resolved |
RESOLVED |
FIXED |
2023-02-22T18:14:26Z |
1614290 |
WISeKey: Unofficial DBA in Organization field |
RESOLVED |
FIXED |
2023-02-22T18:24:18Z |
1614311 |
Telia: Two Intermediate CA certificates not listed in audit report |
RESOLVED |
FIXED |
2024-06-30T20:16:48Z |
1614444 |
Chunghwa Telecom: ALV failures on intermediate certificates |
RESOLVED |
FIXED |
2024-06-30T19:42:44Z |
1614448 |
GRCA: ALV failures on intermediate certificates |
RESOLVED |
FIXED |
2024-06-30T19:45:39Z |
1614449 |
SK ID Solutions: ALV failures on intermediate certificates |
RESOLVED |
FIXED |
2024-06-30T19:48:02Z |
1614450 |
SwissSign: Audit Letter Validation failures on intermediate certificates |
RESOLVED |
WORKSFORME |
2022-11-14T22:22:57Z |
1614821 |
Dhimyotis / Certigna: Intermediate CAs missing audits |
RESOLVED |
FIXED |
2024-06-30T20:05:30Z |
1618256 |
DigiCert: Failure to properly encode Subject name |
RESOLVED |
FIXED |
2023-02-22T18:13:59Z |
1619047 |
Let's Encrypt: CAA Rechecking bug |
RESOLVED |
FIXED |
2023-02-22T18:20:47Z |
1619179 |
Let's Encrypt: Incomplete revocation for CAA rechecking bug |
RESOLVED |
FIXED |
2023-02-22T18:18:54Z |
1619359 |
Sectigo: Failure to provide a preliminary report within 24 hours |
RESOLVED |
FIXED |
2023-02-22T18:25:17Z |
1620561 |
Sectigo: Non-revocation of certificates with subject:organizationalUnitName in DV certificates |
RESOLVED |
FIXED |
2023-02-22T18:23:20Z |
1620727 |
Microsoft DSRE PKI: OCSP responders found to respond signed by the default CA when passed an invalid issuer in request |
RESOLVED |
DUPLICATE |
2023-02-22T18:16:55Z |
1620772 |
SSL.com: Issued precertificate with Debian Weak Key |
RESOLVED |
FIXED |
2023-02-22T18:26:59Z |
1620922 |
GlobalSign: Untimely revocation of TLS certificate after submission of private key compromise |
RESOLVED |
FIXED |
2023-02-22T18:13:16Z |
1622505 |
GlobalSign: OCSP Status HTTP 530 |
RESOLVED |
FIXED |
2023-02-22T18:13:14Z |
1622539 |
Microsec: Issuance of 2 IVCP precertificates without givenName, surName, localityName fields |
RESOLVED |
FIXED |
2023-02-22T18:27:07Z |
1623356 |
GlobalSign: Misissuance of QWAC Certificates |
RESOLVED |
FIXED |
2023-02-22T18:16:31Z |
1623384 |
Camerfirma: Invalid authorityKeyIdentifier - recurrent incident |
RESOLVED |
FIXED |
2023-02-22T18:12:34Z |
1623389 |
Camerfirma: Invalid authorityKeyIdentifier - recurrent incident |
RESOLVED |
DUPLICATE |
2023-02-22T18:28:11Z |
1623472 |
Trustis: Gap between audit periods |
RESOLVED |
FIXED |
2023-02-22T18:13:44Z |
1624504 |
QuoVadis: Failure to revoke certificates with compromised private keys |
RESOLVED |
FIXED |
2023-02-22T18:26:18Z |
1624527 |
DigiCert: Issuance of Cert with Compromised Key |
RESOLVED |
FIXED |
2023-02-22T18:19:34Z |
1624658 |
Camerfirma: BR revocation period exceeded |
RESOLVED |
FIXED |
2023-02-22T18:12:24Z |
1625322 |
Let's Encrypt: Failure to revoke key-compromised certificates within 24 hours |
RESOLVED |
FIXED |
2023-02-22T18:18:51Z |
1625421 |
FNMT: QC Statement that contains at least one of the ETSI ESI statements |
RESOLVED |
INVALID |
2024-05-09T23:21:51Z |
1625445 |
GlobalSign: Failure to revoke 2 noncompliant QWACs within 5 days |
RESOLVED |
FIXED |
2023-02-22T18:23:40Z |
1625498 |
Google Trust Services: Tracking bug for possible audit delays (audit due 2020-12) |
RESOLVED |
INVALID |
2022-11-14T22:22:57Z |
1625715 |
Sectigo: Failure to revoke certificate with previously-compromised key within 24 hours |
RESOLVED |
FIXED |
2023-02-22T18:25:18Z |
1625767 |
Microsec: ALV Failures |
RESOLVED |
FIXED |
2024-06-30T19:45:59Z |
1626078 |
Buypass: Missing NCA identifier in cabfOrganizationIdentifier in PSD2 QWACs |
RESOLVED |
FIXED |
2023-02-22T18:21:47Z |
1626355 |
Atos: Tracking bug for possible audit delays |
RESOLVED |
FIXED |
2023-02-22T18:27:46Z |
1626805 |
FNMT: Minor non-conformities in 2020 audit statement |
RESOLVED |
FIXED |
2023-02-22T18:12:08Z |
1626868 |
WISeKey: Issuance of certificate with two potentially conflicting policy OIDs |
RESOLVED |
FIXED |
2023-02-22T18:24:15Z |
1627152 |
DigiCert: OCSP NextUpdate |
RESOLVED |
FIXED |
2023-02-22T18:14:14Z |
1627346 |
Entrust: S/MIME Certificate Issued with Incorrect Policy OID |
RESOLVED |
FIXED |
2023-02-22T18:14:55Z |
1627614 |
Let's Encrypt: Failure to revoke key-compromised certificates within 24 hours |
RESOLVED |
FIXED |
2023-02-22T18:18:52Z |
1628292 |
Buypass: Failure to revoke PSD2 QWACs within mandated 5 days |
RESOLVED |
FIXED |
2023-02-22T18:21:42Z |
1629020 |
Taiwan-CA: Misissued certificate: Invalid organizationUnitName |
RESOLVED |
FIXED |
2023-02-22T18:18:37Z |
1630040 |
Google Trust Services: OCSP serving issue 2020-04-09 |
RESOLVED |
FIXED |
2023-02-22T18:13:29Z |
1630079 |
Google Trust Services: Invalid OCSP responses |
RESOLVED |
FIXED |
2023-02-22T18:13:28Z |
1630870 |
GlobalSign: Certificate issued with RSASSA-PSS public key |
RESOLVED |
FIXED |
2023-02-22T18:23:37Z |
1632632 |
Buypass: Illegal Business Category in a PSD2 QWAC |
RESOLVED |
FIXED |
2023-02-22T18:21:43Z |
1634795 |
Google Trust Services: Incorrect revocation data temporarily served for GTS Y3 & Y4 |
RESOLVED |
FIXED |
2023-02-22T18:13:25Z |
1635096 |
Entrust: Printable String Constraint Failure |
RESOLVED |
FIXED |
2023-02-22T18:14:53Z |
1635279 |
IdenTrust: Incorrect Subject Details for HydrantId |
RESOLVED |
FIXED |
2023-02-22T18:25:42Z |
1635840 |
Sectigo: Failure to properly respond to a report of subscriber key compromise |
RESOLVED |
FIXED |
2023-02-22T18:25:16Z |
1636140 |
SwissSign: duplicate serial number |
RESOLVED |
FIXED |
2023-02-22T18:22:37Z |
1636141 |
SwissSign: failure to provide a preliminary report within 24 hours |
RESOLVED |
FIXED |
2023-02-22T18:22:41Z |
1636339 |
Entrust: Failure to revoke a certificate |
RESOLVED |
FIXED |
2023-02-22T18:14:42Z |
1636544 |
IdenTrust: OCSP Outage |
RESOLVED |
FIXED |
2023-02-22T18:25:52Z |
1637093 |
Multicert: AIA CA Issuer field pointing to PEM encoded cert |
RESOLVED |
FIXED |
2023-02-22T18:15:13Z |
1637854 |
Telia: AIA CA Issuer field pointing to PEM encoded cert |
RESOLVED |
FIXED |
2023-02-22T18:23:43Z |
1638898 |
T-Systems: "Internet Widgits Pty Ltd" in organizationName |
RESOLVED |
DUPLICATE |
2023-02-22T18:12:50Z |
1639032 |
DigiCert: "Internet Widgits Pty Ltd" in organizationalUnitName |
RESOLVED |
FIXED |
2023-02-22T18:13:52Z |
1639502 |
Asseco DS / Certum: Incorrect OCSP response encoding |
RESOLVED |
FIXED |
2023-02-22T18:28:44Z |
1639518 |
Sectigo: "unauthorized" OCSP responses |
VERIFIED |
INVALID |
2022-11-14T22:22:57Z |
1639794 |
Let's Encrypt: Failure to revoke key-compromised certificate within 24 hours |
RESOLVED |
FIXED |
2023-02-22T18:20:48Z |
1639798 |
GoDaddy: Failure to revoke key-compromised certificates within 24 hours |
RESOLVED |
DUPLICATE |
2023-02-22T18:20:01Z |
1639799 |
GlobalSign: Failure to revoke key-compromised certificate within 24 hours |
RESOLVED |
FIXED |
2023-02-22T18:13:07Z |
1639801 |
DigiCert: Failure to revoke key-compromised certificates within 24 hours |
RESOLVED |
FIXED |
2023-02-22T18:14:03Z |
1639802 |
DigiCert: Failure to revoke key-compromised certificate |
RESOLVED |
FIXED |
2023-02-22T18:14:01Z |
1639804 |
Sectigo: Failure to revoke key-compromised certificate within 24 hours |
RESOLVED |
FIXED |
2023-02-22T18:25:19Z |
1639805 |
Sectigo: Failure to revoke key-compromised certificates |
RESOLVED |
FIXED |
2023-02-22T18:24:48Z |
1640310 |
GoDaddy: Failure to revoke certificate with compromised key within 24 hours |
RESOLVED |
FIXED |
2023-02-22T18:17:03Z |
1640805 |
DigiCert: delayed publication of revocation information |
RESOLVED |
FIXED |
2023-02-22T18:19:23Z |
1644936 |
Microsoft PKI Services: Certificate Mis-Issuance, Locality Missing |
RESOLVED |
FIXED |
2024-05-09T23:27:56Z |
1645276 |
Let's Encrypt: Expired ISRG Root OCSP X1 Certificate |
RESOLVED |
FIXED |
2023-02-22T18:12:03Z |
1645686 |
Sectigo: Lack of input validation in stateOrProvinceName |
RESOLVED |
DUPLICATE |
2023-02-22T18:24:50Z |
1645708 |
QuoVadis: EV serialNumber with "none" |
RESOLVED |
FIXED |
2023-02-22T18:26:17Z |
1645832 |
GoDaddy: Expired CRLs |
RESOLVED |
FIXED |
2023-02-22T18:17:02Z |
1646226 |
GoDaddy: Document Reuse Issue |
RESOLVED |
FIXED |
2023-02-22T18:17:00Z |
1646711 |
SecureTrust: Metadata-only field values in 2 certificates |
RESOLVED |
FIXED |
2023-02-22T18:15:31Z |
1646866 |
DigiCert: Failure to revoke invalid serialNumber EV certificates within 5 days |
RESOLVED |
INVALID |
2022-11-14T22:22:57Z |
1647030 |
GoDaddy: Agreed-Upon Website Domain Validation Method Issue |
RESOLVED |
FIXED |
2024-06-30T03:30:15Z |
1647084 |
DigiCert / Microsoft: inconsistent disclosure of externally-operated intermediate |
RESOLVED |
FIXED |
2023-02-22T18:19:09Z |
1647099 |
Camerfirma: Delayed revocations related to Invalid authorityKeyIdentifier - recurrent incident |
RESOLVED |
FIXED |
2023-02-22T18:12:29Z |
1647121 |
Izenpe: Failure to provide a preliminary report within 24 hours. |
RESOLVED |
FIXED |
2023-02-22T18:23:24Z |
1647468 |
D-TRUST: Wrong key usage (Key Encipherment) |
RESOLVED |
FIXED |
2023-02-22T18:17:15Z |
1648472 |
Entrust: SHA-256 hash algorithm used with ECC P-384 key |
RESOLVED |
FIXED |
2024-06-30T05:20:18Z |
1648593 |
Sectigo: Potential audit report delay |
RESOLVED |
FIXED |
2024-06-30T19:47:44Z |
1648717 |
Sectigo: Failure to provide a preliminary report within 24 hours. |
RESOLVED |
FIXED |
2023-02-22T18:24:47Z |
1648840 |
Let's Encrypt: OCSP responses with no revocationReason |
RESOLVED |
FIXED |
2023-02-22T18:20:50Z |
1648997 |
Actalis: inaccurate value in stateOrProvinceName |
RESOLVED |
FIXED |
2023-02-22T18:11:56Z |
1649277 |
DigiCert: Failure to provide a preliminary report within 24 hours. |
RESOLVED |
FIXED |
2023-02-22T18:14:00Z |
1649502 |
Firmaprofesional: 2020 Audit Report Finding 1 out of 4 |
RESOLVED |
FIXED |
2023-02-22T18:15:52Z |
1649507 |
Network Solutions: Audit report delay |
RESOLVED |
FIXED |
2024-06-30T19:46:45Z |
1649679 |
Firmaprofesional: 2020 Audit Report Finding 2 out of 4 |
RESOLVED |
FIXED |
2023-02-22T18:22:58Z |
1649683 |
Telia: Qualified BR Audit Statement 2020 |
RESOLVED |
FIXED |
2023-02-22T18:24:02Z |
1649724 |
Firmaprofesional: 2020 Audit Report Finding 3 out of 4 |
RESOLVED |
FIXED |
2023-02-22T18:22:59Z |
1649726 |
Firmaprofesional: 2020 Audit Report Finding 4 out of 4 |
RESOLVED |
FIXED |
2023-02-22T18:23:00Z |
1649880 |
QuoVadis: Failure to provide a preliminary report within 24 hours. |
RESOLVED |
FIXED |
2023-02-22T18:26:27Z |
1649937 |
GlobalSign: Incorrect OCSP Delegated Responder Certificate |
RESOLVED |
FIXED |
2023-02-22T18:16:29Z |
1649938 |
QuoVadis: Incorrect OCSP Delegated Responder Certificate |
RESOLVED |
FIXED |
2023-02-22T18:26:35Z |
1649939 |
WISeKey: Incorrect OCSP Delegated Responder Certificate |
RESOLVED |
FIXED |
2023-02-22T18:24:12Z |
1649941 |
T-Systems: Incorrect OCSP Delegated Responder Certificate |
RESOLVED |
FIXED |
2023-02-22T18:12:53Z |
1649942 |
SK ID Solutions: Incorrect OCSP Delegated Responder Certificate |
RESOLVED |
FIXED |
2023-02-22T18:21:26Z |
1649943 |
Firmaprofesional: Incorrect OCSP Delegated Responder Certificate |
RESOLVED |
FIXED |
2023-02-22T18:15:54Z |
1649944 |
Camerfirma: Incorrect OCSP Delegated Responder Certificate |
RESOLVED |
FIXED |
2023-02-22T18:17:25Z |
1649945 |
HARICA: Incorrect OCSP Delegated Responder Certificate |
RESOLVED |
FIXED |
2023-02-22T18:20:10Z |
1649947 |
Microsec: Incorrect OCSP Delegated Responder Certificate |
RESOLVED |
FIXED |
2023-02-22T18:27:06Z |
1649951 |
DigiCert: Incorrect OCSP Delegated Responder Certificate |
RESOLVED |
FIXED |
2023-02-22T18:22:23Z |
1649961 |
Actalis: Incorrect OCSP Delegated Responder Certificate |
RESOLVED |
FIXED |
2023-02-22T18:11:57Z |
1649962 |
SECOM: Incorrect OCSP Delegated Responder Certificate |
RESOLVED |
FIXED |
2023-02-22T18:18:23Z |
1649963 |
Atos: Incorrect OCSP Delegated Responder Certificate |
RESOLVED |
FIXED |
2023-02-22T18:27:44Z |
1649964 |
PKIoverheid: Incorrect OCSP Delegated Responder Certificate |
RESOLVED |
FIXED |
2023-02-22T18:20:38Z |
1650018 |
GlobalSign: Cross Certificate with non-conforming CABF Policy OIDs |
RESOLVED |
FIXED |
2023-02-22T18:13:05Z |
1650234 |
PKIoverheid / QuoVadis: CPS inconsistencies |
RESOLVED |
FIXED |
2023-02-22T18:26:13Z |
1650845 |
Sectigo: CPR response issues |
RESOLVED |
FIXED |
2024-06-30T20:26:48Z |
1650910 |
DigiCert: Inconsistent EV audits |
RESOLVED |
FIXED |
2023-02-22T18:14:05Z |
1651026 |
Izenpe: certificate issued to internal domain |
RESOLVED |
FIXED |
2023-02-22T18:23:23Z |
1651132 |
T-Systems / DFN-PKI: 42 certificates with RSA modulus size in bits not divisable by 8 |
RESOLVED |
FIXED |
2023-02-22T18:13:49Z |
1651447 |
GlobalSign: Failure to revoke noncompliant ICA within 7 days |
RESOLVED |
FIXED |
2023-02-22T18:13:10Z |
1651461 |
DigiCert: Failure to revoke within 7 days: OCSP EKU issue |
RESOLVED |
FIXED |
2023-02-22T18:14:04Z |
1651465 |
HARICA: Delayed revocation for non-BR-compliant CA Certificates within 7 days |
RESOLVED |
FIXED |
2023-02-22T18:20:09Z |
1651481 |
Entrust: Late Revocation due to SHA-256 hash algorithm |
RESOLVED |
FIXED |
2023-02-22T18:14:48Z |
1651487 |
Telekom Security: Delayed Revocations of Sub-CA certificates |
RESOLVED |
FIXED |
2023-02-22T18:12:59Z |
1651553 |
QuoVadis: Failure to revoke within 7 days: OCSP EKU issue |
RESOLVED |
FIXED |
2023-02-22T18:26:29Z |
1651611 |
Telekom Security: Finding in 2020 ETSI-Audit regarding weekly review of changes to configurations |
RESOLVED |
FIXED |
2023-02-22T18:13:00Z |
1651632 |
Microsec: Failure to revoke noncompliant ICA within 7 days |
RESOLVED |
FIXED |
2023-02-22T18:27:05Z |
1651637 |
Firmaprofesional: Failure to revoke ICAs within 7 days: OCSP EKU |
RESOLVED |
FIXED |
2023-02-22T18:23:10Z |
1651651 |
Actalis: Failure to revoke within 7 days: OCSP EKU issue |
RESOLVED |
FIXED |
2023-02-22T18:11:55Z |
1651730 |
WISeKey: Failure to revoke ICA Certificates within 7 days (OCSP EKU) |
RESOLVED |
FIXED |
2023-02-22T18:24:11Z |
1651828 |
DigiCert: Delay of revocation for EV audit inconsistency incident |
RESOLVED |
FIXED |
2023-02-22T18:13:56Z |
1652581 |
Google Trust Services: digitalSignature KeyUsage not set |
RESOLVED |
FIXED |
2023-02-22T18:13:21Z |
1652603 |
Camerfirma: Failure to revoke within 7 days: OCSP EKU issue |
RESOLVED |
FIXED |
2023-02-22T18:17:24Z |
1652604 |
PKIoverheid: Failure to revoke within 7 days: OCSP EKU issue |
RESOLVED |
FIXED |
2023-02-22T18:20:37Z |
1652610 |
SECOM: Delayed Revocation of CA Certificate with OCSP EKU Issue |
RESOLVED |
FIXED |
2023-02-22T18:18:08Z |
1652827 |
Microsoft PKI Services: Incomplete Logical Access Review Audit Evidence |
RESOLVED |
FIXED |
2024-06-30T18:52:20Z |
1652922 |
PKIoverheid: Failure to revoke within 7 days: OCSP EKU issue |
RESOLVED |
DUPLICATE |
2023-02-22T18:15:09Z |
1653284 |
Izenpe: incorrect value in stateOrProvinceName |
RESOLVED |
FIXED |
2023-02-22T18:23:27Z |
1653475 |
DigiCert: Key Size Not Divisible By 8 |
RESOLVED |
FIXED |
2023-02-22T18:19:37Z |
1653504 |
Sectigo: Certificates with RSA keys where modulus is not divisible by 8 |
RESOLVED |
FIXED |
2023-02-22T18:23:18Z |
1653680 |
IdenTrust: OCSP Responder missing id-pkix-ocsp-nocheck |
RESOLVED |
FIXED |
2023-02-22T18:25:53Z |
1654216 |
Buypass: PSD2 QWAC with RSA modulus not divisible by 8 |
RESOLVED |
FIXED |
2023-02-22T18:21:49Z |
1654544 |
GlobalSign: Use of Domain Validation Random Value for more than 30 days |
RESOLVED |
FIXED |
2023-02-22T18:13:17Z |
1654545 |
GlobalSign: Failure to revoke noncompliant certificates within 5 days |
RESOLVED |
FIXED |
2023-02-22T18:13:08Z |
1654896 |
GlobalSign: Certificates with RSA keys where modulus is not divisible by 8 |
RESOLVED |
FIXED |
2023-02-22T18:13:04Z |
1654967 |
DigiCert: Malformed ICA |
RESOLVED |
FIXED |
2023-02-22T18:22:24Z |
1655698 |
Telekom Security: CRL also contained unrevoked certificates |
RESOLVED |
FIXED |
2023-02-22T18:12:58Z |
1656487 |
Izenpe: Failure to revoke within 5 days |
RESOLVED |
FIXED |
2023-02-22T18:23:25Z |
1656882 |
NetLock: Failure to revoke noncompliant ICA within 7 days |
RESOLVED |
FIXED |
2023-02-22T18:27:48Z |
1658437 |
Let's Encrypt: intent to issue root and intermediate certificates with organizationName and CABF DV OID |
RESOLVED |
WORKSFORME |
2024-05-09T19:16:46Z |
1658792 |
Entrust: Invalid data in State/Province Field |
RESOLVED |
FIXED |
2023-02-22T18:16:18Z |
1658794 |
Entrust: Late Revocation for Invalid State/Province Issue |
RESOLVED |
FIXED |
2023-02-22T18:16:21Z |
1658932 |
GlobalSign: Incorrect Jurisdiction of Incorporation information for Japan |
RESOLVED |
FIXED |
2023-02-22T18:17:33Z |
1658995 |
Microsoft PKI Services: Firewall log data retention |
RESOLVED |
FIXED |
2024-05-09T23:27:58Z |
1659316 |
Apple: EV Certificate Approver Authorization |
RESOLVED |
FIXED |
2023-02-22T18:15:37Z |
1659426 |
E-Tugra: audit delay because of an environmental disaster/pandemic |
RESOLVED |
FIXED |
2024-06-30T19:44:06Z |
1662137 |
SwissSign: OCSP responder unreachable |
RESOLVED |
FIXED |
2023-02-22T18:22:50Z |
1662346 |
DigiCert: OCSP responder returning invalid responses |
RESOLVED |
FIXED |
2023-02-22T18:22:25Z |
1662382 |
GDCA: Incorrect Value in organizationName Field |
RESOLVED |
FIXED |
2023-02-22T18:15:29Z |
1662807 |
GoDaddy: Certificates issued with validity periods greater than 398-days |
RESOLVED |
FIXED |
2023-02-22T18:19:57Z |
1662810 |
GoDaddy: DV certificates with organizationalUnit field in subject |
RESOLVED |
FIXED |
2023-02-22T18:20:00Z |
1663080 |
IdenTrust: Issuance of certificates greater than 398 days |
RESOLVED |
FIXED |
2023-02-22T18:25:45Z |
1663953 |
TunTrust: OCSP unreachable |
RESOLVED |
FIXED |
2023-02-22T18:24:31Z |
1664325 |
DigiCert: SHA-256 hash algorithm used with ECC P-384 key |
RESOLVED |
DUPLICATE |
2023-02-22T18:14:16Z |
1664328 |
GlobalSign: SHA-256 hash algorithm used with ECC P-384 key |
RESOLVED |
FIXED |
2023-02-22T18:13:15Z |
1665688 |
eMudhra: emSign CA ECC Test Certificate Misissuance |
RESOLVED |
FIXED |
2023-02-22T18:28:01Z |
1665763 |
Sectigo: Failure to revoke within 5 days |
RESOLVED |
FIXED |
2023-02-22T18:24:49Z |
1666047 |
Let's Encrypt: 302 total OCSP responses available beyond acceptable timelines |
RESOLVED |
FIXED |
2023-02-22T18:20:55Z |
1666872 |
SSL.com: Insufficient validation evidence for the localityName attribute of an OV certificate |
RESOLVED |
FIXED |
2023-02-22T18:26:53Z |
1667430 |
Camerfirma: Invalid stateOrProvinceName field |
RESOLVED |
FIXED |
2023-02-22T18:12:35Z |
1667448 |
Entrust: Incorrect keyUsage for ECC certificate |
RESOLVED |
FIXED |
2023-02-22T18:14:43Z |
1667518 |
QuoVadis: Incorrect keyUsage for ECC certificate |
RESOLVED |
FIXED |
2023-02-22T18:26:34Z |
1667684 |
Asseco DS / Certum: Failure to provide a preliminary report within 24 hours. |
RESOLVED |
FIXED |
2023-02-22T18:28:41Z |
1667690 |
Entrust: Failure to provide a preliminary report within 24 hours. |
RESOLVED |
FIXED |
2023-02-22T18:16:15Z |
1667744 |
Dhimyotis / Certigna: Certificates issued with validity periods greater than 398-days |
RESOLVED |
FIXED |
2023-02-22T18:18:44Z |
1667799 |
SecureTrust: Failure to provide a preliminary report within 24 hours. |
RESOLVED |
FIXED |
2023-02-22T18:12:41Z |
1667842 |
SecureTrust: Inaccurate value in stateOrProvinceName |
RESOLVED |
FIXED |
2023-02-22T18:12:42Z |
1667844 |
Google Trust Services: Certificates not disclosed in CCADB |
RESOLVED |
FIXED |
2023-02-22T18:24:51Z |
1667846 |
Izenpe: Certificates not disclosed in CCADB |
RESOLVED |
INVALID |
2022-11-14T22:22:57Z |
1667944 |
GlobalSign: Empty SingleExtension in OCSP responses |
RESOLVED |
FIXED |
2023-02-22T18:23:38Z |
1667986 |
Asseco DS / Certum: Invalid stateOrProvinceName field |
RESOLVED |
FIXED |
2023-02-22T18:12:19Z |
1668005 |
GlobalSign: Failure to provide a preliminary report within 24 hours |
RESOLVED |
FIXED |
2023-02-22T18:13:06Z |
1668007 |
GlobalSign: Invalid stateOrProvinceName value |
RESOLVED |
FIXED |
2023-02-22T18:13:13Z |
1668331 |
Camerfirma: Delayed revocations related to Invalid stateOrProvinceName field |
RESOLVED |
FIXED |
2023-02-22T18:22:13Z |
1668523 |
Asseco DS / Certum: Failure to revoke within 5 days |
RESOLVED |
FIXED |
2023-02-22T18:12:21Z |
1669518 |
PKIoverheid: Overdue audit statements for intermediate certificates |
RESOLVED |
FIXED |
2024-06-30T19:47:11Z |
1669594 |
IdenTrust: Issuance of Subordinate CA’s Without EKU |
RESOLVED |
FIXED |
2023-02-22T18:25:47Z |
1669618 |
Apple: Empty SingleExtension in OCSP responses |
RESOLVED |
FIXED |
2023-02-22T18:15:37Z |
1670337 |
Microsoft PKI Services: Certificate Mis-Issuance, DNSNames must have a valid TLD |
RESOLVED |
FIXED |
2024-01-16T01:00:23Z |
1670458 |
Disig: Failure to provide a preliminary report within 24 hours. |
RESOLVED |
FIXED |
2023-02-22T18:24:05Z |
1670861 |
Actalis: delayed revocation related to inaccurate value in stateOrProvinceName |
RESOLVED |
FIXED |
2023-02-22T18:11:54Z |
1670894 |
SwissSign: Invalid stateOrProvinceName field |
RESOLVED |
FIXED |
2023-02-22T18:22:44Z |
1671037 |
SecureTrust: CPS section 6.1.1.1 number 3 non-compliance event |
RESOLVED |
FIXED |
2023-02-22T18:12:39Z |
1671113 |
SwissSign: Failure to provide a preliminary report within 24 hours. |
RESOLVED |
FIXED |
2023-02-22T18:22:42Z |
1671410 |
IdenTrust: Inconsistent Disclosure of Externally-Operated Intermediate |
RESOLVED |
FIXED |
2024-06-30T02:08:37Z |
1672029 |
Camerfirma: Failure to abide by Section 8 of Mozilla Policy: Unauthorized, improperly disclosed Subordinate CA |
RESOLVED |
FIXED |
2023-02-22T18:12:31Z |
1672208 |
DFN-PKI: Finding in 2020 ETSI audit |
RESOLVED |
FIXED |
2023-02-22T18:13:46Z |
1672409 |
Camerfirma: suspicious certificate for com.com |
RESOLVED |
FIXED |
2023-02-22T18:12:38Z |
1672423 |
Camerfirma: certificate for unregistered domain cuatis.net |
RESOLVED |
FIXED |
2023-02-22T18:12:25Z |
1672562 |
Camerfirma: Incorrect disclosure of Intesa Sanpaolo sub-CA |
RESOLVED |
FIXED |
2023-02-22T18:12:33Z |
1673119 |
Entrust: Subscriber provides private key with CSR |
RESOLVED |
FIXED |
2023-02-22T18:15:00Z |
1674082 |
Dhimyotis / Certigna: Certificates issued with validity periods greater than 398-days |
RESOLVED |
FIXED |
2023-02-22T18:24:34Z |
1674536 |
Telia: Certificates with RSA keys where modulus is not divisible by 8 |
RESOLVED |
FIXED |
2023-02-22T18:23:45Z |
1674561 |
Microsoft PKI Services: DV certificate issued with OV fields |
RESOLVED |
FIXED |
2023-02-22T18:16:57Z |
1674886 |
certSIGN: misissued an OV SSL certificate with no organizationName and localityName, instead of a DV SSL as requested by client |
RESOLVED |
FIXED |
2023-02-22T18:18:01Z |
1675295 |
Entrust: Invalid data in commonName fields |
RESOLVED |
INVALID |
2022-11-14T22:22:57Z |
1675314 |
Telekom Security: Wrong jurisdiction entries in certificates |
RESOLVED |
FIXED |
2023-02-22T18:13:03Z |
1675684 |
DigiCert: Private Keys Disclosed by Customers as Part of CSR |
RESOLVED |
FIXED |
2023-02-22T18:19:44Z |
1675923 |
DigiCert: TERENA: Insufficient validation of organizationalUnitName |
RESOLVED |
INVALID |
2024-05-09T23:40:11Z |
1676003 |
DigiCert: Entity not verified in organizationalUnitName |
RESOLVED |
FIXED |
2023-02-22T18:19:28Z |
1676352 |
Microsec: Certificate validity period greater than 398 days |
RESOLVED |
FIXED |
2023-02-22T18:27:02Z |
1676367 |
NetLock: Issuance of >398-day precertificates after 2020-09-01 |
RESOLVED |
FIXED |
2023-02-22T18:27:54Z |
1676440 |
NetLock: Cumulative report connected to EV verification |
RESOLVED |
FIXED |
2023-02-22T18:27:51Z |
1677234 |
Apple: OCSP availability 2020-11-12 |
RESOLVED |
FIXED |
2023-02-22T18:15:40Z |
1677239 |
IdenTrust: Service Degradation |
RESOLVED |
FIXED |
2023-02-22T18:25:57Z |
1677737 |
SwissSign: duplicate serial number |
RESOLVED |
FIXED |
2023-02-22T18:22:39Z |
1678183 |
Google Trust Services: Invalid ASN.1 encoding of singleExtensions in OCSP responses |
RESOLVED |
FIXED |
2023-02-22T18:13:26Z |
1678410 |
IdenTrust: Invalid OCSP Response Held in Cache |
RESOLVED |
FIXED |
2023-02-22T18:25:44Z |
1678720 |
SSL.com: Wildcard DV certificate issued with a non-validated domain name |
RESOLVED |
FIXED |
2023-02-22T18:27:00Z |
1680083 |
Camerfirma: certificate with an incorrect OrganizationName |
RESOLVED |
FIXED |
2023-02-22T18:17:21Z |
1680378 |
NetLock: Replacement of enduser certificates after the EVGL 1.7.4 self-audit |
RESOLVED |
FIXED |
2023-02-22T18:13:32Z |
1682270 |
D-TRUST: Private Key Disclosed by Customer as Part of CSR |
RESOLVED |
FIXED |
2023-02-22T18:17:12Z |
1684112 |
Let's Encrypt: Failure to audit log subscriber certificate OCSP updates |
RESOLVED |
FIXED |
2023-02-22T18:12:04Z |
1684442 |
DigiCert: SHA-1 intermediate issued after 2016-01-01 |
RESOLVED |
FIXED |
2023-02-22T18:19:45Z |
1685142 |
Dhimyotis / Certigna: Failure to revoke in the timeline specified by the BRs |
RESOLVED |
DUPLICATE |
2023-02-22T18:24:36Z |
1685370 |
Entrust: Incorrect Business Category Value Discovered in an EV SSL Certificate |
RESOLVED |
FIXED |
2023-02-22T18:16:16Z |
1685557 |
Camerfirma: Certificates without CABForum OV Reserved Policy Identifier |
RESOLVED |
FIXED |
2023-02-22T18:12:26Z |
1685767 |
Izenpe: Multiple sub CAs with incorrectly encoded SubjectPublicKeyInfo algorithm |
RESOLVED |
DUPLICATE |
2023-02-22T18:23:30Z |
1686524 |
Camerfirma: Certificate issued with 3-year lifespan, unknown policy |
RESOLVED |
FIXED |
2023-02-22T18:17:20Z |
1686966 |
Camerfirma: Delayed revocations related to certificates without CABForum OV Reserved Policy Identifier |
RESOLVED |
FIXED |
2023-02-22T18:12:28Z |
1687139 |
E-Tugra: commonName not in SAN |
RESOLVED |
FIXED |
2023-02-22T18:16:43Z |
1687330 |
E-Tugra: Intermittent OCSP response with status 'Unknown' |
RESOLVED |
FIXED |
2023-02-22T18:16:51Z |
1687513 |
E-Tugra: Delayed Response of Revocation Request |
RESOLVED |
FIXED |
2023-02-22T18:16:44Z |
1687608 |
E-Tugra: The failure to revoke a certificate |
RESOLVED |
FIXED |
2023-02-22T18:16:53Z |
1688215 |
Camerfirma: CP/CPS of Intesa Sanpaolo Sub-CA is Non-Compliant |
RESOLVED |
FIXED |
2023-02-22T18:12:27Z |
1688382 |
Camerfirma: No disclosure of verification sources |
RESOLVED |
FIXED |
2023-02-22T18:12:36Z |
1688844 |
NetLock: Delayed revocation report connected to ticket 1680378 |
RESOLVED |
FIXED |
2023-02-22T18:27:52Z |
1689589 |
Telia: Disallowed curve (P-521) in leaf certificate |
RESOLVED |
FIXED |
2023-02-22T18:23:50Z |
1690807 |
GlobalSign: RSA-1024 leaf certificate issued after 2013-12-31 |
RESOLVED |
FIXED |
2023-02-22T18:17:36Z |
1691117 |
D-TRUST: Certificate with RSA key where modulus is not divisible by 8 |
RESOLVED |
FIXED |
2023-02-22T18:17:04Z |
1691704 |
SwissSign: Certificate with key length 4098 bit |
RESOLVED |
FIXED |
2023-02-22T18:22:34Z |
1692533 |
Camerfirma: Old CAs with an RSA modulus size of 2047 bits |
RESOLVED |
FIXED |
2023-02-22T18:12:37Z |
1692535 |
Camerfirma: Delayed revocations of certificates issued by old CAs with an RSA modulus size of 2047 bits |
RESOLVED |
FIXED |
2023-02-22T18:15:04Z |
1693304 |
FNMT: Issuance of QCP-n certificates without verifying identity |
RESOLVED |
FIXED |
2023-02-22T18:12:07Z |
1693343 |
DigiCert: Failure to find and revoke key-compromised certificates within 24 hours |
RESOLVED |
FIXED |
2023-02-22T18:19:29Z |
1693930 |
Microsoft PKI Services: Policy Documentation, Failure to update Subscriber Certificate Max Validity Period |
RESOLVED |
FIXED |
2023-02-22T18:20:26Z |
1693932 |
Microsoft PKI Services: Policy Documentation, Failure to update Domain Validation Method |
RESOLVED |
FIXED |
2023-02-22T18:20:25Z |
1694233 |
Sectigo: Inadequate DCV |
RESOLVED |
FIXED |
2023-02-22T18:27:14Z |
1695786 |
SECOM: Unqualified domain name in SAN |
RESOLVED |
FIXED |
2023-02-22T18:18:31Z |
1695938 |
SECOM: FUJIFILM intermediate CA Certificate not listed in audit statement |
RESOLVED |
FIXED |
2024-06-30T20:12:14Z |
1695993 |
SECOM: Outdated audit statements for intermediate certificates |
RESOLVED |
FIXED |
2024-06-30T20:12:30Z |
1696227 |
Entrust: Incorrect Jurisdiction Country Value in an EV Certificate |
RESOLVED |
FIXED |
2023-02-22T18:16:17Z |
1696872 |
FNMT: Missisuance of web site certificates without CA/Browser Forum’s reserved policy OID |
RESOLVED |
FIXED |
2025-03-20T06:26:37Z |
1698936 |
Sectigo: ZeroSSL: failure to revoke within 24 hours |
RESOLVED |
FIXED |
2023-02-22T18:27:30Z |
1699756 |
Sectigo: Reseller ZeroSSL and Private Key Generation |
RESOLVED |
INVALID |
2022-11-14T22:22:57Z |
1699796 |
HARICA: Certificates with invalid policy tree |
RESOLVED |
FIXED |
2023-02-22T18:20:08Z |
1700145 |
Firmaprofesional: incorrect reserved CA/B Forum OIDs in certificates |
RESOLVED |
FIXED |
2023-02-22T18:15:55Z |
1700809 |
Microsoft PKI Services: Failure to disclose Unconstrained Intermediate within 7 Days |
RESOLVED |
FIXED |
2023-02-22T18:20:23Z |
1703528 |
Telekom Security: Key Encipherment in two ECC SAN TLS certificates |
RESOLVED |
FIXED |
2023-02-22T18:13:01Z |
1704140 |
Camerfirma: Govern d'Andorra Audit Delay |
RESOLVED |
FIXED |
2024-06-30T19:42:12Z |
1704199 |
FNMT: Minor non-conformities in 2021 audit statement |
RESOLVED |
FIXED |
2023-02-22T18:26:06Z |
1705187 |
KIR S.A.: CN domain not in SAN |
RESOLVED |
FIXED |
2023-02-22T18:24:21Z |
1705337 |
KIR S.A.: Invalid localityName + CRL Revoked but OCSP Unknown |
RESOLVED |
FIXED |
2023-02-22T18:24:26Z |
1705419 |
Microsoft PKI Services: Underscore in SAN |
RESOLVED |
FIXED |
2023-02-22T18:20:27Z |
1705480 |
SECOM: CP/CPS does not clearly specify domain validation methods |
RESOLVED |
FIXED |
2023-02-22T18:18:15Z |
1705647 |
KIR S.A.: Invalid organizationName |
RESOLVED |
FIXED |
2023-02-22T18:24:27Z |
1705657 |
KIR S.A.: Many certificates with OCSP Unknown |
RESOLVED |
FIXED |
2023-02-22T18:24:28Z |
1705791 |
Telekom Security: Multiple commonName in certificates |
RESOLVED |
FIXED |
2023-02-22T18:13:02Z |
1705832 |
KIR S.A.: DV certificates with locality name, organization name and stateOrProvinceName |
RESOLVED |
FIXED |
2023-02-22T18:24:25Z |
1705904 |
KIR S.A.: CP/CPS contains noncompliant DV method, does not specify CAA domains |
RESOLVED |
FIXED |
2023-02-22T18:24:23Z |
1706860 |
Microsoft PKI Services: Certificate Mis-Issuance, DNSName is not FQDN, Preferred Name Syntax |
RESOLVED |
FIXED |
2023-02-22T18:20:20Z |
1706950 |
PKIoverheid: KPN issued Invalid organizationalUnitName |
RESOLVED |
FIXED |
2023-02-22T18:20:40Z |
1706967 |
Google Trust Services: Forbidden Domain Validation Method 3.2.2.4.10 |
RESOLVED |
FIXED |
2023-02-22T18:13:24Z |
1706976 |
Google Trust Services: Out-of-date CPS disclosure |
RESOLVED |
INVALID |
2022-11-14T22:22:57Z |
1707073 |
GlobalSign: Invalid countryName |
RESOLVED |
FIXED |
2023-02-22T18:17:35Z |
1707229 |
SECOM: Delayed Revocation of non-technically constrained FUJIFILM Certificates |
RESOLVED |
FIXED |
2023-02-22T18:18:17Z |
1708516 |
Google Trust Services: Failure to provide regular and timely incident updates |
RESOLVED |
FIXED |
2023-02-22T18:13:23Z |
1708834 |
GlobalSign: Invalid stateOrProvinceName and locality pair |
RESOLVED |
FIXED |
2023-02-22T18:13:12Z |
1708934 |
Sectigo: Invalid postalCode field |
RESOLVED |
FIXED |
2023-02-22T18:27:20Z |
1708965 |
KIR S.A.: Certificates issued greater than stated in CPS |
RESOLVED |
FIXED |
2023-02-22T18:24:19Z |
1709070 |
Taiwan-CA: Invalid stateOrProvinceName |
RESOLVED |
FIXED |
2023-02-22T18:18:36Z |
1709192 |
IdenTrust: Unavailable CRL for IdenTrust ‘DST Root CA X3’. |
RESOLVED |
FIXED |
2023-02-22T18:25:59Z |
1709223 |
Google Trust Services: Signing SHA-1 Hash for existing CA certificate with changes in Key Usage |
RESOLVED |
FIXED |
2023-02-22T18:24:52Z |
1709392 |
Asseco DS / Certum: Invalid stateOrProvinceName field (recurrent incident) |
RESOLVED |
FIXED |
2023-02-22T18:12:20Z |
1709872 |
KIR S.A.: Delayed revocations of certificates |
RESOLVED |
FIXED |
2023-02-22T18:24:24Z |
1709896 |
Certigna: certificates issued with 2 SCT |
RESOLVED |
INVALID |
2024-05-09T21:00:11Z |
1710206 |
Asseco DS / Certum: Incorrect localityName |
RESOLVED |
INVALID |
2022-11-14T22:22:57Z |
1710243 |
Sectigo: Invalid stateOrProvinceName |
RESOLVED |
FIXED |
2023-02-22T18:25:02Z |
1710444 |
DigiCert: Invalid stateOrProvinceName |
RESOLVED |
FIXED |
2023-02-22T18:14:10Z |
1710856 |
DigiCert: Invalid localityName |
RESOLVED |
FIXED |
2023-02-22T18:14:09Z |
1711147 |
Microsoft PKI Services: Malformed ICAs (missing certificate policy extensions) |
RESOLVED |
FIXED |
2023-02-22T18:20:24Z |
1711208 |
Asseco DS / Certum: Incorrect localityName |
RESOLVED |
FIXED |
2023-02-22T18:12:18Z |
1711432 |
Telekom Security: Certificate with invalid FQDN |
RESOLVED |
FIXED |
2023-02-22T18:12:57Z |
1712106 |
Entrust: Invalid localityName |
RESOLVED |
FIXED |
2023-02-22T18:16:19Z |
1712120 |
Sectigo: Inappropriate subject:serialNumber information in EV certificates obtained through ACME |
RESOLVED |
FIXED |
2023-02-22T18:27:15Z |
1712188 |
Sectigo: test certificates issued from trusted CA |
RESOLVED |
FIXED |
2023-02-22T18:27:27Z |
1712664 |
iTrusChina: verification errors for the roots' CRLs(ARL) |
RESOLVED |
FIXED |
2023-02-22T18:28:06Z |
1713668 |
Amazon Trust Services: ALV Errors |
RESOLVED |
FIXED |
2023-02-22T18:27:35Z |
1713976 |
Amazon Trust Services: CP/CPS does not specify key compromise methods |
RESOLVED |
FIXED |
2023-02-22T18:27:36Z |
1713978 |
Amazon Trust Services: Forbidden Domain Validation Method 3.2.2.4.6 |
RESOLVED |
FIXED |
2023-02-22T18:27:37Z |
1714193 |
Sectigo: Incorrect locality information |
RESOLVED |
FIXED |
2023-02-22T18:27:19Z |
1714439 |
DigiCert: Incorrect RegNumber-Org Type combination |
RESOLVED |
FIXED |
2023-02-22T18:14:06Z |
1714628 |
Sectigo: Forbidden Domain Validation Method |
RESOLVED |
FIXED |
2023-02-22T18:27:13Z |
1714968 |
GlobalSign: Incorrect RegNumber-Org Type combination |
RESOLVED |
FIXED |
2023-02-22T18:17:34Z |
1715024 |
Sectigo: Misspellings in stateOrProvince or localityName fields |
RESOLVED |
FIXED |
2023-02-22T18:27:23Z |
1715421 |
Google Trust Services: Failure to revoke subscriber certificates within BR timeframe |
RESOLVED |
FIXED |
2023-02-22T18:17:47Z |
1715455 |
Let's Encrypt: certificate lifetimes 90 days plus one second |
RESOLVED |
FIXED |
2024-01-10T13:38:25Z |
1715672 |
Let's Encrypt: Failure to revoke for Certificate Lifetime Incident |
RESOLVED |
FIXED |
2023-02-22T18:10:13Z |
1715929 |
Sectigo: Incorrect EV businessCategory |
RESOLVED |
FIXED |
2023-02-22T18:27:17Z |
1716123 |
e-commerce monitoring GmbH: CN domain not in SAN |
RESOLVED |
FIXED |
2024-05-25T18:46:20Z |
1716163 |
e-commerce monitoring GmbH: Revoked test website not using revoked certificate |
RESOLVED |
FIXED |
2024-05-25T18:52:21Z |
1716670 |
TWCA: Intermediate CA Certificate Missing from Audit Reports |
RESOLVED |
FIXED |
2024-06-30T20:17:54Z |
1716843 |
E-Tugra: Intermediate CA Certificate Missing from Audit Reports |
RESOLVED |
FIXED |
2024-06-30T20:07:16Z |
1716874 |
NetLock: Intermediate CA Certificate Missing from Audit Reports |
RESOLVED |
FIXED |
2024-06-30T20:09:34Z |
1716902 |
E-Tugra: Forbidden Domain Validation Method 3.2.2.4.6 |
RESOLVED |
FIXED |
2023-02-22T18:16:48Z |
1717001 |
Disig: CPS does not refer to BR domain validation methods |
RESOLVED |
INVALID |
2022-11-14T22:22:57Z |
1717034 |
Asseco DS / Certum: CPS does not refer to BR domain validation methods |
RESOLVED |
FIXED |
2023-02-22T18:12:15Z |
1717044 |
SECOM: Intermediate CA Certificates Missing from Audit Reports |
RESOLVED |
FIXED |
2024-06-30T20:11:56Z |
1717046 |
Sectigo: potentially invalid organizational validation certificates |
RESOLVED |
INVALID |
2022-11-14T22:22:57Z |
1717357 |
Actalis: Issuance of intermediates after 2020-08-20 that do not comply with Mozilla Policy and the Baseline Requirements |
RESOLVED |
FIXED |
2023-02-22T18:12:00Z |
1717790 |
Firmaprofesional: 2021 Audit Report Finding 1 out of 3 |
RESOLVED |
FIXED |
2023-02-22T18:23:02Z |
1717791 |
Firmaprofesional: 2021 Audit Report Finding 2 out of 3 |
RESOLVED |
FIXED |
2023-02-22T18:23:03Z |
1717795 |
Firmaprofesional: 2021 Audit Report Finding 3 out of 3 |
RESOLVED |
FIXED |
2023-02-22T18:23:04Z |
1718517 |
Netlock: Error in latest audit report |
RESOLVED |
DUPLICATE |
2024-05-09T23:20:15Z |
1718552 |
IdenTrust: Certificates with Invalid values for stateOrProvinceName |
RESOLVED |
FIXED |
2023-02-22T18:25:33Z |
1718554 |
Actalis: Delayed revocation of non-BR-compliant CA Certificate within 7 days |
RESOLVED |
FIXED |
2023-02-22T18:11:53Z |
1718579 |
Sectigo: "Manual DCV" method used |
RESOLVED |
FIXED |
2023-02-22T18:27:10Z |
1718675 |
certSIGN: CPS specifies md5 and sha1WithRSAEncryption as useable signature types |
RESOLVED |
FIXED |
2023-02-22T18:17:58Z |
1718680 |
Asseco DS / Certum: Forward dating certificates (notBefore in the future) |
RESOLVED |
FIXED |
2023-02-22T18:12:16Z |
1718771 |
Sectigo: DCV Reuse after 825 days |
RESOLVED |
FIXED |
2023-02-22T18:24:59Z |
1718785 |
Sectigo: 2020 failure to respond to CPRs discovered |
RESOLVED |
FIXED |
2024-06-30T20:26:27Z |
1718991 |
Microsoft PKI Services: Malformed ICAs (Key Usage Malformed) |
RESOLVED |
FIXED |
2024-05-09T19:16:04Z |
1719451 |
PKIoverheid: KPN CPS Lists Forbidden Domain Validation Method 3.2.2.4.6 |
RESOLVED |
FIXED |
2023-02-22T18:16:23Z |
1719916 |
SSL.com: Issuance of an EV TLS certificate with incorrect O Field Value |
RESOLVED |
FIXED |
2023-02-22T18:26:57Z |
1719920 |
Amazon Trust Services: Revocation Time for Intermediate Certificates |
RESOLVED |
FIXED |
2023-02-22T18:28:07Z |
1720723 |
SecureTrust: Invalid localityName |
RESOLVED |
FIXED |
2023-02-22T18:12:44Z |
1720744 |
Sectigo: State name in localityName |
RESOLVED |
FIXED |
2023-02-22T18:27:25Z |
1721271 |
Sectigo: Missing registration numbers in EV certificates |
RESOLVED |
FIXED |
2023-02-22T18:27:21Z |
1721473 |
Web.com: Overdue Audit Statements 2021 |
RESOLVED |
FIXED |
2024-06-30T19:48:43Z |
1722089 |
SSL.com: Issuance of 3 EV TLS certificates without 2-person validation of the organization information |
RESOLVED |
FIXED |
2023-02-22T18:26:56Z |
1723121 |
Web.com: Failure to respond in time to revocation requests |
RESOLVED |
FIXED |
2023-02-22T18:21:02Z |
1724276 |
QuoVadis / PKIoverheid: incorrect OCSP response for precertificate |
RESOLVED |
FIXED |
2023-02-22T18:26:42Z |
1724458 |
Sectigo: Mojibake in certificate Subject fields |
RESOLVED |
FIXED |
2023-02-22T18:27:24Z |
1724485 |
SecureTrust: Delayed revocation of a customer revoke request |
RESOLVED |
FIXED |
2023-02-22T18:12:40Z |
1724520 |
SSL.com: Incorrect Domain Validation for 1 TLS certificate with FQDN having "www." string within domain labels |
RESOLVED |
FIXED |
2023-02-22T18:26:52Z |
1724528 |
Apple: Intermediate CA certificates omitted from audit statement |
RESOLVED |
FIXED |
2024-06-30T20:04:00Z |
1724530 |
Microsoft PKI Services: Overdue Audit Reports 2021 |
RESOLVED |
FIXED |
2024-06-30T19:46:23Z |
1725039 |
Network Solutions: 2021 Audit Observation #1 |
RESOLVED |
FIXED |
2023-02-22T18:20:57Z |
1725041 |
Network Solutions: 2021 Audit Observation #2 |
RESOLVED |
DUPLICATE |
2023-02-22T18:20:59Z |
1725043 |
Network Solutions: 2021 Audit Observation #3 |
RESOLVED |
FIXED |
2023-02-22T18:21:00Z |
1725047 |
Network Solutions: 2021 Audit Findings 1-3 |
RESOLVED |
DUPLICATE |
2023-02-22T18:20:56Z |
1726333 |
Network Solutions: All test CA test website certificates are expired |
RESOLVED |
FIXED |
2023-02-22T18:21:01Z |
1727963 |
DigiCert: Truncation of Registration Number |
RESOLVED |
FIXED |
2023-02-22T18:19:48Z |
1728384 |
Microsec: Misissuance of one OV certificate with Key Usage KeyEncipherment |
RESOLVED |
FIXED |
2023-02-22T18:27:08Z |
1728790 |
eMudhra: Audit Delay |
RESOLVED |
FIXED |
2024-06-30T19:44:30Z |
1728796 |
Entrust: Incorrect value in Business Category field for Government Entities |
RESOLVED |
FIXED |
2023-02-22T18:23:42Z |
1729097 |
Google Trust Services: Delayed publication of CPS removing DNS Operator Exception |
RESOLVED |
FIXED |
2023-02-22T18:23:36Z |
1729567 |
Let's Encrypt: Delay updating OCSP responses |
RESOLVED |
FIXED |
2023-02-22T18:10:11Z |
1730291 |
Apple: Test website certificates expired |
RESOLVED |
FIXED |
2024-06-30T19:11:36Z |
1731164 |
Google Trust Services: CRL validity period set to expected value plus one second |
RESOLVED |
FIXED |
2023-02-22T18:15:18Z |
1731586 |
SwissSign: Certificate with key length 16258 |
RESOLVED |
FIXED |
2023-02-22T18:22:33Z |
1731887 |
Entrust: Test Website Certificates Expired |
RESOLVED |
FIXED |
2023-02-22T18:15:01Z |
1731939 |
GoDaddy: Issued EV Wildcard Certificate |
RESOLVED |
FIXED |
2023-02-22T18:14:32Z |
1732484 |
Sectigo: Truncated registration numbers in EV certificates |
RESOLVED |
FIXED |
2023-02-22T18:27:29Z |
1732745 |
Certainly: Root CRL validity period exceeds maximum by one second |
RESOLVED |
FIXED |
2023-02-22T18:28:12Z |
1733000 |
QuoVadis: revocation services validity set to expected value plus one second |
RESOLVED |
FIXED |
2023-02-22T18:26:39Z |
1734114 |
Netlock: Problem with NETLOCK's codesigning CA |
RESOLVED |
INVALID |
2024-05-09T19:15:29Z |
1734131 |
SwissSign: wrong address in EV certificate |
RESOLVED |
FIXED |
2023-02-22T18:22:51Z |
1734265 |
GoDaddy: Root CRLs exceed maximum validity period by 1 second |
RESOLVED |
FIXED |
2023-02-22T18:14:36Z |
1734906 |
IdenTrust: Intermitent interruptions to DNS service |
RESOLVED |
FIXED |
2023-02-22T18:25:31Z |
1734917 |
IdenTrust: Mis-Issued EV Certificates |
RESOLVED |
FIXED |
2023-02-22T18:25:48Z |
1734953 |
GoDaddy: CPR responses greater than 24 hours |
RESOLVED |
FIXED |
2024-06-30T20:23:46Z |
1735247 |
Let's Encrypt: Mis-issued certificates related to SC48v2 |
RESOLVED |
FIXED |
2023-02-22T18:20:15Z |
1735761 |
Sectigo: CRL validity beyond CPS allowed value |
RESOLVED |
FIXED |
2023-02-22T18:27:12Z |
1735908 |
SHECA: UniTrust: Improper DER results in failure to comply with RFC 5280 - Encoded sequence component with default value |
RESOLVED |
FIXED |
2023-11-29T22:28:42Z |
1735998 |
SECOM: Root CRLs exceed maximum validity period by 1 second |
RESOLVED |
FIXED |
2023-02-22T18:18:28Z |
1736020 |
Telia: Invalid email contact address was used for few domains |
RESOLVED |
FIXED |
2023-02-22T18:23:47Z |
1736064 |
Sectigo: Subject field with unvalidated information included in certificates |
RESOLVED |
FIXED |
2023-02-22T18:27:26Z |
1736706 |
IdenTrust: Failure to Revoke Subscriber Certificates Within 5 days |
RESOLVED |
FIXED |
2023-02-22T18:25:40Z |
1737057 |
Entrust: CRLs and OCSP responses not issued as specified in the CPS |
RESOLVED |
FIXED |
2023-02-22T18:14:41Z |
1737242 |
Cybertrust Japan: Root CRLs exceed maximum validity period by one second |
RESOLVED |
FIXED |
2023-02-22T18:22:27Z |
1737808 |
Telia: Delayed revocation of 5 EE certificates in connection to id=1736020 |
RESOLVED |
FIXED |
2023-02-22T18:23:46Z |
1738191 |
GDCA: CRL validity period exceeds allowed value by one second |
RESOLVED |
FIXED |
2023-02-22T18:15:26Z |
1738207 |
Telia: Issued three precertificates with non-NIST EC curve |
RESOLVED |
FIXED |
2023-02-22T18:23:48Z |
1738421 |
Izenpe: CRL and ARL exceed validity period value by one second |
RESOLVED |
FIXED |
2023-02-22T18:16:10Z |
1738472 |
QuoVadis: hostnames not in preferred name syntax |
RESOLVED |
FIXED |
2023-02-22T18:26:31Z |
1738778 |
TWCA: Policy OID not set to indicate the assurance level to the issued certs |
RESOLVED |
FIXED |
2023-02-22T18:18:39Z |
1740493 |
Sectigo: Failure to block disallowed LDH labels in domain names |
RESOLVED |
FIXED |
2023-02-22T18:22:04Z |
1740585 |
Microsoft PKI Services: Unrevoked 4 intermediate certificates |
RESOLVED |
FIXED |
2024-05-09T23:28:00Z |
1741026 |
Sectigo: Incorrect JOI for federal credit unions |
RESOLVED |
FIXED |
2023-02-22T18:27:18Z |
1741497 |
CFCA: Overdue Audit Statements 2021 |
RESOLVED |
FIXED |
2023-03-02T19:04:33Z |
1741777 |
Sectigo: OCSP responses directly signed using root certificates without KU=digitalSignature |
RESOLVED |
FIXED |
2023-02-22T18:25:04Z |
1742195 |
Microsoft PKI Services: Failure to disclose Revocation of Intermediate CAs within 7 Days |
RESOLVED |
FIXED |
2023-02-22T18:20:22Z |
1742602 |
GoDaddy: Reported TLS Certificate Private Key Exposure |
RESOLVED |
DUPLICATE |
2023-02-22T18:14:35Z |
1742657 |
GoDaddy: Failure to Revoke Subscriber Certificates within 24 hours |
RESOLVED |
FIXED |
2023-02-22T18:14:31Z |
1742704 |
Let's Encrypt: Potential Denial of Service against websites with broad private key reuse |
RESOLVED |
FIXED |
2024-05-09T19:15:02Z |
1743935 |
Amazon Trust Services: Misissuance of Subordinate Per CPS |
RESOLVED |
FIXED |
2023-02-22T18:27:38Z |
1743943 |
Amazon Trust Services: Delayed Revocation of Subordinate CA |
RESOLVED |
FIXED |
2023-06-02T15:24:38Z |
1744518 |
GlobalSign: EV certificates with serialNumber Government Entity and businessCategory Private Organization |
RESOLVED |
FIXED |
2023-02-22T18:23:39Z |
1744627 |
IdenTrust: Issuance of OV SSL Certificate with doc vetting older than 398 days |
RESOLVED |
FIXED |
2023-02-22T18:25:46Z |
1744722 |
FNMT: Invalid localityName |
RESOLVED |
FIXED |
2023-02-22T18:12:06Z |
1744795 |
DigiCert: Issuance of certs with weak keys (ROCA) |
RESOLVED |
FIXED |
2023-02-22T18:19:35Z |
1744827 |
Entrust: SSL Certificates issued with Un-verified IP Addresses |
RESOLVED |
FIXED |
2024-03-08T07:27:48Z |
1745015 |
eMudhra: emSign CA Invalid OrganizationalUnitName |
RESOLVED |
FIXED |
2023-02-22T18:28:00Z |
1746421 |
PKIoverheid: (KPN) Incorrect Subject OrganizationName |
RESOLVED |
FIXED |
2023-02-22T18:16:22Z |
1746945 |
Amazon Trust Services: Missing CAA Check For Test Website Certificates |
RESOLVED |
FIXED |
2023-02-22T18:27:39Z |
1747915 |
Sectigo: Incorrect JOI Country value |
RESOLVED |
FIXED |
2023-02-22T18:22:07Z |
1748634 |
Entrust: Late Revocation for SSL Certificates issued with Un-verified IP Addresses |
RESOLVED |
FIXED |
2023-02-22T18:14:49Z |
1749089 |
IdenTrust: OCSP Signer Certificate Missing No-Check Extension |
RESOLVED |
FIXED |
2023-02-22T18:25:55Z |
1750631 |
SSL.com: Issuance of TLS certificates with domain validation methods prohibited by SC-45 |
RESOLVED |
FIXED |
2024-06-30T03:32:01Z |
1751984 |
Let's Encrypt: TLS Using ALPN TLS Version and OID |
RESOLVED |
FIXED |
2023-02-22T18:11:51Z |
1752452 |
Certainly: TLS Using ALPN TLS Version and OID |
RESOLVED |
FIXED |
2023-02-22T18:28:15Z |
1752636 |
SSL.com: Delayed revocation of 53 certificates affected by bug #1750631 |
RESOLVED |
FIXED |
2023-02-22T18:26:52Z |
1752670 |
Let's Encrypt: TLS Using ALPN Allows Additional Identifiers in Challenge Certificate |
RESOLVED |
FIXED |
2024-05-09T23:25:04Z |
1753123 |
Let's Encrypt: Failure to provide OCSP Responses for some certificates |
RESOLVED |
FIXED |
2023-01-04T17:50:21Z |
1753287 |
IdenTrust: Validation Source for EV Certificates not Publicly Disclosed |
RESOLVED |
FIXED |
2024-07-08T21:40:25Z |
1754593 |
IdenTrust: Unavailable CRL and OCSP Responders |
RESOLVED |
FIXED |
2023-02-22T18:25:58Z |
1756122 |
D-TRUST: Wrong key usage (Key Agreement) |
RESOLVED |
FIXED |
2023-02-22T18:17:14Z |
1756261 |
IdenTrust: EV TLS certificate with invalid Jurisdiction state for government entity |
RESOLVED |
FIXED |
2023-02-22T18:25:36Z |
1756847 |
Sectigo: SC45 DCV Reuse Error |
RESOLVED |
FIXED |
2023-02-22T18:22:10Z |
1756850 |
IdenTrust: EV TLS certificate with wrong jurisdiction state for private organization |
RESOLVED |
FIXED |
2023-02-22T18:25:37Z |
1757247 |
IdenTrust: Delay Revocation for EV SSL Certificates |
RESOLVED |
FIXED |
2023-02-22T18:25:34Z |
1757615 |
Amazon Trust Services: Overdue audit statements for intermediate certificates |
RESOLVED |
FIXED |
2024-06-30T19:41:17Z |
1758027 |
IdenTrust: Pre-certificates without a final certificate showing OCSP error |
RESOLVED |
FIXED |
2023-02-22T18:25:56Z |
1758213 |
IdenTrust: Failure to provide OCSP responses for valid ICA certificates |
RESOLVED |
FIXED |
2023-02-22T18:25:39Z |
1758372 |
Google Trust Services: Incorrect OCSP response for issued certificate |
RESOLVED |
FIXED |
2023-02-22T18:15:20Z |
1759854 |
GlobalSign: Certificate issued to FQDN with malformed CAA |
RESOLVED |
FIXED |
2023-02-22T18:16:00Z |
1759959 |
GoDaddy: OV Documentation Reuse |
RESOLVED |
FIXED |
2023-02-22T18:14:34Z |
1760311 |
GlobalSign: OCSP responder certificates with more than 64 characters in CN |
RESOLVED |
FIXED |
2023-02-22T18:16:03Z |
1762456 |
QuoVadis: Failure to provide a preliminary report within 24 hours |
RESOLVED |
INVALID |
2022-11-14T22:22:57Z |
1762707 |
certSIGN: Subscriber precertificate without Certificate Policies |
RESOLVED |
FIXED |
2023-02-22T18:27:47Z |
1763173 |
certSIGN: Incorrect data in stateOrProvinceName |
RESOLVED |
FIXED |
2023-02-22T18:17:59Z |
1763203 |
Sectigo: Incorrect OCSP responses |
RESOLVED |
FIXED |
2023-02-22T18:22:08Z |
1763700 |
eMudhra: emSign CA Invalid AIA Extension Value |
RESOLVED |
FIXED |
2023-02-22T18:27:59Z |
1765800 |
SecureTrust: Incorrect OCSP response |
RESOLVED |
FIXED |
2023-02-22T18:12:43Z |
1766255 |
SwissSign: Mis-Issuance of S/MIME certificates |
RESOLVED |
FIXED |
2023-02-22T18:22:45Z |
1766525 |
Entrust: TLS Certificate issued with a key that is impacted by the Close Primes vulnerability |
RESOLVED |
FIXED |
2023-02-22T18:15:02Z |
1769222 |
SECOM: Failed an annual CPS update of Cybertrust Japan (CTJ) |
RESOLVED |
FIXED |
2024-06-30T20:37:36Z |
1769240 |
Firmaprofesional: 2022 - SSL certificates issued with wrong Organization ID number |
RESOLVED |
FIXED |
2023-02-22T18:23:07Z |
1770510 |
Google Trust Services: Failure to provide preliminary report within 24h |
RESOLVED |
FIXED |
2023-05-04T21:31:12Z |
1771238 |
Certainly: Serving Expired OCSP Responses |
RESOLVED |
FIXED |
2023-02-22T18:28:14Z |
1771398 |
Apple: OCSP responders return ‘unknown’ for valid S/MIME and TLS certificates |
RESOLVED |
FIXED |
2023-02-22T18:15:41Z |
1771482 |
CFCA: Precertificate with postalCode and streetAddress swapped |
RESOLVED |
FIXED |
2023-02-22T18:13:43Z |
1771552 |
Google Trust Services: OCSP responses not published in a timely manner |
RESOLVED |
FIXED |
2023-02-22T18:15:24Z |
1771715 |
Firmaprofesional: 2022 - StateorProvince field |
RESOLVED |
FIXED |
2023-02-22T18:23:08Z |
1771722 |
Firmaprofesional: 2022 - Title field |
RESOLVED |
FIXED |
2023-02-22T18:23:09Z |
1771724 |
Firmaprofesional: 2022 - CPS without correct explanation about difference between OCSP and CRL |
RESOLVED |
FIXED |
2023-02-22T18:23:05Z |
1771727 |
Firmaprofesional: 2022 - Define Device Obsolescence Process |
RESOLVED |
FIXED |
2023-02-22T18:23:06Z |
1772411 |
NAVER Cloud Trust Services: Failure to Respond to May 2022 Survey |
RESOLVED |
FIXED |
2024-05-09T23:31:18Z |
1772412 |
iTrusChina: Failure to Respond to May 2022 Survey |
RESOLVED |
FIXED |
2023-03-20T15:03:39Z |
1772413 |
eMudhra: Failure to Respond to May 2022 Survey |
RESOLVED |
FIXED |
2023-03-20T15:03:21Z |
1772414 |
E-Tugra: Failure to Respond to May 2022 Survey |
RESOLVED |
FIXED |
2023-02-22T18:16:46Z |
1772633 |
IdenTrust: OCSP responses for subordinate CA exceed the validity period per CPS guidelines |
RESOLVED |
FIXED |
2023-02-22T18:25:54Z |
1772644 |
Apple: CRL issuance frequency deviates from CPS in some cases |
RESOLVED |
FIXED |
2023-02-22T18:15:34Z |
1773556 |
Google Trust Services: Incorrect OCSP responses for certain certificates |
RESOLVED |
FIXED |
2023-02-22T18:15:21Z |
1774171 |
Certigna: Precertificate with a validity period greater than 398-days |
RESOLVED |
DUPLICATE |
2023-02-22T18:15:06Z |
1774418 |
Certigna: Certificate issued with validity period greater than 398-days |
RESOLVED |
FIXED |
2023-04-19T22:27:37Z |
1775454 |
IdenTrust: CRL Potential Publication Delay due to Cache |
RESOLVED |
FIXED |
2023-02-22T18:25:32Z |
1776764 |
SecureTrust: 2 certificates with non-DER encoded keyUsage extension |
RESOLVED |
FIXED |
2023-04-13T19:30:06Z |
1777128 |
GoDaddy: Misissuance of Cross Signed Certs |
RESOLVED |
FIXED |
2023-02-22T18:14:33Z |
1777270 |
Certainly: Intermediate certificates with wrong time encoding |
RESOLVED |
DUPLICATE |
2023-02-22T18:15:05Z |
1777757 |
Apple: EV TLS pre-certificates issued without EKU extension |
RESOLVED |
FIXED |
2023-02-22T18:15:39Z |
1778035 |
CFCA: The wrong status of OCSP |
RESOLVED |
FIXED |
2023-04-19T22:28:04Z |
1778788 |
IdenTrust: Intermittent issuance/validation failures and website outage |
RESOLVED |
FIXED |
2023-02-22T18:25:27Z |
1782356 |
Sectigo: Misspelled city name in localityName field |
RESOLVED |
FIXED |
2023-02-22T18:27:22Z |
1782391 |
GlobalSign: EV certificate with wildcard domain in common name and SAN |
RESOLVED |
FIXED |
2023-02-22T18:16:02Z |
1783272 |
Google Trust Services: Failure to send preliminary report to subscriber within 24h |
RESOLVED |
FIXED |
2023-02-22T18:21:33Z |
1784820 |
CFCA: Delayed reporting of intermediate CA certificate |
RESOLVED |
FIXED |
2023-08-16T20:34:22Z |
1784881 |
SwissSign: Missed deadline of publication of 6 CPs and 1 CP/CPS |
RESOLVED |
FIXED |
2023-02-22T18:22:49Z |
1785865 |
NAVER Cloud Trust Services: DV certificate issued with no subject alternative name extension |
RESOLVED |
FIXED |
2024-05-09T23:31:11Z |
1786313 |
DFN-PKI: OCSP/CRL inconsistencies |
RESOLVED |
FIXED |
2023-02-22T18:13:47Z |
1787537 |
UniTrust: EV certificate with wildcard domain in common name and SAN |
RESOLVED |
FIXED |
2023-04-19T22:24:53Z |
1789521 |
Let's Encrypt: Certificates issued to Elliptic Curve Debian Weak Keys |
RESOLVED |
FIXED |
2024-05-09T23:24:57Z |
1790693 |
SSL.com: Issuance of 1 EV TLS certificate using a Registration/Incorporation Agency not included in our approved public list. |
RESOLVED |
FIXED |
2023-03-24T16:11:39Z |
1792111 |
IdenTrust: Expired CRLs |
RESOLVED |
FIXED |
2023-02-22T18:25:30Z |
1792231 |
Entrust: TLS Certificate issued with an incorrect state or province |
RESOLVED |
FIXED |
2023-04-19T22:25:51Z |
1793053 |
CFCA: ICA without EKU |
RESOLVED |
FIXED |
2023-06-30T16:29:50Z |
1793059 |
CFCA: The delay in revocation of ICA |
RESOLVED |
FIXED |
2023-06-30T16:30:04Z |
1793114 |
Let's Encrypt: Incomplete and Inconsistent CRLs |
RESOLVED |
FIXED |
2023-02-22T18:11:50Z |
1793440 |
D-TRUST: CRL not DER-encoded |
RESOLVED |
FIXED |
2023-02-22T18:17:05Z |
1793441 |
GlobalSign: CRL contains invalid signature algorithm |
RESOLVED |
FIXED |
2023-02-22T18:16:01Z |
1793443 |
Microsoft PKI Services: "unknown" OCSP response for issued certificates |
RESOLVED |
FIXED |
2024-05-09T23:28:02Z |
1793445 |
TWCA: "unknown" OCSP response for issued certificates |
RESOLVED |
FIXED |
2023-04-19T22:26:05Z |
1793467 |
Google Trust Services: invalid CRL reason code |
RESOLVED |
FIXED |
2023-02-22T18:15:22Z |
1793642 |
GoDaddy: CRLs are version 1 and lack CRL Number extension |
RESOLVED |
FIXED |
2023-01-15T18:11:01Z |
1793692 |
WISeKey: Issuance of certificate with non-DER encoded keyUsage |
RESOLVED |
FIXED |
2023-02-22T18:24:14Z |
1793787 |
Sectigo: Non-existent hostname in CDP and AIA URLs |
RESOLVED |
FIXED |
2023-02-22T18:22:09Z |
1793789 |
Sectigo: Incorrect JOI |
RESOLVED |
FIXED |
2023-02-22T18:22:06Z |
1793848 |
GoDaddy: Failure to revoke 210 subscriber certificates within 24 hours |
RESOLVED |
FIXED |
2023-02-22T18:14:30Z |
1794047 |
IdenTrust: Missing Revocation Reasons in CRL |
RESOLVED |
FIXED |
2023-02-22T18:25:28Z |
1794050 |
DigiCert: Org information issue in new validation workflow |
RESOLVED |
FIXED |
2023-02-22T18:19:43Z |
1795483 |
Let's Encrypt: Delayed revocation for removed gTLD |
RESOLVED |
FIXED |
2023-02-22T18:19:02Z |
1796715 |
IdenTrust: Mis-Issued EV Code Signing Certificate |
RESOLVED |
FIXED |
2023-02-22T18:25:49Z |
1796803 |
Sectigo: Issuance of ECC leaf certificates with non-DER encoded keyUsage |
RESOLVED |
FIXED |
2023-02-22T18:25:03Z |
1797165 |
DigiCert: Delayed Revocation of ~5.5 hours |
RESOLVED |
FIXED |
2023-02-22T18:19:24Z |
1798053 |
Certainly: Serving Bad OCSP Responses |
RESOLVED |
FIXED |
2023-02-22T18:28:13Z |
1798316 |
SwissSign: 'c/o' in streetAddress of EV certificate |
RESOLVED |
FIXED |
2023-02-22T18:22:32Z |
1798626 |
SHECA: UniTrust: EV certificate with wrong Registry Country Name |
RESOLVED |
FIXED |
2023-11-29T22:28:29Z |
1798812 |
CFCA: Delayed reporting of revocation of an intermediate CA certificate |
RESOLVED |
FIXED |
2023-05-04T21:31:28Z |
1799755 |
Let's Encrypt: End Entity CRLs Not Reissued On Time |
RESOLVED |
FIXED |
2024-05-09T23:24:49Z |
1800405 |
Amazon Trust Services / DigiCert: 404 error when fetching CRL |
RESOLVED |
FIXED |
2023-02-22T18:27:34Z |
1800753 |
SSL.com: Delayed revocation of certificate with weak key |
RESOLVED |
WONTFIX |
2023-07-21T16:04:41Z |
1800756 |
Sectigo: Failure to revoke ECC certificates with non-DER encoded keyUsage within 5 days |
RESOLVED |
FIXED |
2023-02-22T18:22:05Z |
1801345 |
E-Tugra: Incident Report (Security Issues) |
RESOLVED |
FIXED |
2023-07-21T15:45:27Z |
1802845 |
CFCA: EV certificate with wrong PostalCode&Street |
RESOLVED |
FIXED |
2023-09-29T15:32:49Z |
1802916 |
Entrust: EV TLS Certificate incorrect jurisdiction |
RESOLVED |
FIXED |
2023-04-24T19:50:18Z |
1804587 |
WISeKey: Bad ECDSA algorithm encoding in test certificate |
RESOLVED |
FIXED |
2023-02-03T22:28:11Z |
1804753 |
Entrust: Delayed Revocation for EV TLS Certificate incorrect jurisdiction |
RESOLVED |
FIXED |
2023-04-19T22:26:20Z |
1804843 |
Hongkong Post: Subject CN converted to Unicode representation incident |
RESOLVED |
FIXED |
2023-04-19T22:25:15Z |
1805866 |
SECOM: One of the EV certificate was mis-issued with the incorrect Registration Number by Cybertrust Japan (CTJ) |
RESOLVED |
FIXED |
2023-02-02T01:51:38Z |
1806728 |
IdenTrust: Bad OCSP Responses |
RESOLVED |
FIXED |
2023-05-05T20:09:41Z |
1808485 |
WISeKey: Incorrect businessCategory in EV certificate |
RESOLVED |
FIXED |
2023-02-03T22:27:55Z |
1809382 |
CFCA: Certificate with wrong crlDistributionPoints |
RESOLVED |
FIXED |
2023-09-29T15:33:03Z |
1809864 |
Google Trust Services: Mis-issued certificates for citi.com subdomain due to lack of CAA record checking |
RESOLVED |
INVALID |
2024-05-09T23:21:26Z |
1812336 |
Sectigo: Late CCADB update after CPS update |
RESOLVED |
FIXED |
2023-02-10T16:58:18Z |
1813989 |
Sectigo: Incomplete Subject organizationName |
RESOLVED |
FIXED |
2023-05-04T21:28:52Z |
1814197 |
DigiCert: Late CP/CPS CCADB uploads |
RESOLVED |
FIXED |
2023-02-14T20:36:53Z |
1814288 |
SHECA: Delayed revocation of intermediate CA certificates |
RESOLVED |
FIXED |
2023-04-07T15:31:30Z |
1815355 |
Asseco DS / Certum: Cross-Signed non-EV-audited root with an EV-enabled root |
RESOLVED |
FIXED |
2023-08-16T20:34:36Z |
1815466 |
SwissSign: CRL/OCSP revocation time mismatch |
RESOLVED |
FIXED |
2023-04-19T22:25:32Z |
1815527 |
SHECA: organizationName problems in OV and EV TLS certificates |
RESOLVED |
FIXED |
2023-11-29T22:28:15Z |
1815534 |
e-commerce monitoring GmbH: SCT in precertificate |
RESOLVED |
FIXED |
2024-04-17T17:37:45Z |
1815874 |
Google Trust Services: incorrect SCT in certificate |
RESOLVED |
FIXED |
2023-03-20T17:05:08Z |
1816806 |
DigiCert: OCSP not responding issue |
RESOLVED |
FIXED |
2023-03-09T21:36:21Z |
1817023 |
Microsoft PKI Services: Failure to modify policy documents within 365 days |
RESOLVED |
FIXED |
2024-05-09T23:28:04Z |
1818073 |
Sectigo: Late revocation for incomplete Subject organizationName |
RESOLVED |
FIXED |
2023-06-28T16:51:41Z |
1818833 |
IdenTrust: Inaccurate CRL Details in CCADB |
RESOLVED |
FIXED |
2023-03-20T17:04:44Z |
1819105 |
NETLOCK: Disclosed CRL is expired |
RESOLVED |
FIXED |
2023-09-29T15:33:37Z |
1819422 |
Certainly: CRL Issuing Distribution Point Mismatch in CCADB |
RESOLVED |
FIXED |
2023-03-24T16:11:21Z |
1820174 |
NETLOCK: SSL certificates with OU field |
RESOLVED |
FIXED |
2023-07-28T22:14:47Z |
1820269 |
DigiCert: 4 CRLs unavailable or not responding |
RESOLVED |
FIXED |
2024-06-30T18:35:27Z |
1821508 |
eMudhra: CRL occasionally unavailable and returns 404 error |
RESOLVED |
FIXED |
2024-06-30T18:37:37Z |
1822809 |
NETLOCK: SSL certificates with OU field - revocation delay |
RESOLVED |
FIXED |
2023-09-29T15:34:03Z |
1823040 |
Asseco DS / Certum: Cross-certificate with wrong policy identifier |
RESOLVED |
FIXED |
2023-05-19T20:59:32Z |
1823723 |
Sectigo: Incomplete Subscriber Agreement provisions |
RESOLVED |
FIXED |
2023-04-05T16:52:17Z |
1824206 |
DigiCert: Inconsistent validation information |
RESOLVED |
FIXED |
2023-04-07T15:35:10Z |
1824257 |
WISeKey: Pre-certificates revoked with certificateHold reason |
RESOLVED |
FIXED |
2023-05-04T21:28:09Z |
1824319 |
Actalis: pre-certificates with “certificateHold” as the revocation reason |
RESOLVED |
FIXED |
2023-07-20T23:23:59Z |
1824435 |
NETLOCK: Invalid CT data in issued certs (SABRE.CT misconfiguration) |
RESOLVED |
INVALID |
2023-05-04T22:02:51Z |
1825232 |
SwissSign: Invalid CT data in issued certs (SABRE.CT misconfiguration) |
RESOLVED |
INVALID |
2023-03-31T16:47:58Z |
1825734 |
Asseco DS / Certum: Delayed revocation of SHECA cross certificate |
RESOLVED |
FIXED |
2023-06-01T16:09:16Z |
1825780 |
Telekom Security: Improper use of a domain validation method |
RESOLVED |
FIXED |
2023-07-05T19:37:15Z |
1826235 |
VikingCloud: Incorrect organizationName |
RESOLVED |
FIXED |
2023-09-02T17:58:32Z |
1826363 |
Asseco DS / Certum: Delayed revocation of SSL.COM cross certificate |
RESOLVED |
FIXED |
2023-06-08T16:43:53Z |
1826713 |
Actalis: Certificates issued with validity period greater than 398 days |
RESOLVED |
FIXED |
2023-07-20T23:24:14Z |
1827490 |
Cybertrust Japan: CRL signature algorithm encoding error |
RESOLVED |
FIXED |
2023-06-02T15:25:20Z |
1827772 |
DigiCert: Org-JOI type mismatch |
RESOLVED |
FIXED |
2023-05-04T21:26:43Z |
1828105 |
Telia: Misissued certificate - wrong OrganizationName value "Hair 8 Brains" |
RESOLVED |
FIXED |
2023-06-30T16:29:21Z |
1828717 |
FNMT: CRL problems displayed during the monitoring |
RESOLVED |
FIXED |
2023-09-29T15:32:36Z |
1829024 |
GoDaddy: CRL Issuer Mismatch |
RESOLVED |
FIXED |
2023-05-05T20:09:23Z |
1829195 |
GlobalSign: CRLs reported in CCADB unavailable |
RESOLVED |
FIXED |
2023-05-04T21:28:27Z |
1829746 |
Sectigo: Certificate issuance delayed for more than 398 days after DCV was completed |
RESOLVED |
FIXED |
2023-06-02T15:24:51Z |
1830088 |
Sectigo: Late termination of privileged access to Certificate Systems |
RESOLVED |
FIXED |
2024-03-27T16:06:53Z |
1830536 |
e-commerce monitoring gmbh: certificate issued with two pre-certificates |
RESOLVED |
FIXED |
2024-05-11T00:31:48Z |
1830823 |
NETLOCK: Pre-certificates revoked with certificateHold reason |
RESOLVED |
FIXED |
2023-08-04T16:10:19Z |
1831004 |
IdenTrust: duplicate Certificate in error flagged by OCSP Watch |
RESOLVED |
FIXED |
2024-05-09T19:13:23Z |
1832093 |
Asseco DS / Certum: Subordinate certificates with sequential serial number |
RESOLVED |
FIXED |
2023-06-02T15:25:04Z |
1832338 |
Firmaprofesional: 2023 - Ensure Timestamp service Logs Integrity |
RESOLVED |
FIXED |
2023-06-08T16:44:58Z |
1832342 |
Firmaprofesional: 2023 - documentary inconsistency |
RESOLVED |
FIXED |
2023-10-12T10:25:32Z |
1832570 |
SSL.com: subCA/Reseller Issues |
RESOLVED |
FIXED |
2024-06-14T17:07:39Z |
1833667 |
certSIGN: Findings in 2023 ETSI Audit for certSIGN ROOT CA G2 - Audit Incident Report |
RESOLVED |
FIXED |
2023-11-19T22:01:50Z |
1836443 |
GlobalSign: Issuance of test certificate (pre-certificate) for EV SSL/QWAC with no EKU extension |
RESOLVED |
FIXED |
2024-06-30T19:20:32Z |
1836694 |
Hongkong Post: Invalid EV cert businessCategory |
RESOLVED |
FIXED |
2023-09-29T15:35:32Z |
1837386 |
ANF AC: 2023 Audit Report Finding |
RESOLVED |
FIXED |
2023-10-12T10:24:44Z |
1837519 |
Google Trust Services: Failure to respond to CPR within 24 hours |
RESOLVED |
FIXED |
2023-11-02T16:07:47Z |
1838315 |
IdenTrust: Certificate with missing details flagged by OCSP Watch |
RESOLVED |
FIXED |
2023-10-12T10:25:58Z |
1838334 |
DigiCert: Sub CA with EV OIDs without audit report |
RESOLVED |
FIXED |
2023-06-26T15:41:25Z |
1838371 |
CFCA: certificate with an incorrect OrganizationName |
RESOLVED |
FIXED |
2024-01-19T15:21:51Z |
1838421 |
Buypass: Domain validation method using not allowed domain contact |
RESOLVED |
FIXED |
2024-06-30T03:27:01Z |
1838667 |
Let's Encrypt: Duplicate Serial Numbers |
RESOLVED |
FIXED |
2023-07-05T19:33:50Z |
1838707 |
Google Trust Services: Revocation data publication delay for revoked unused subordinate CAs |
RESOLVED |
FIXED |
2023-07-28T22:11:25Z |
1838765 |
SHECA: Outdated Organizational Units (OUs) problems in OV TLS certificates |
RESOLVED |
FIXED |
2023-11-29T22:27:38Z |
1838860 |
Tuntrust: Failure to Respond to April 2023 Survey |
RESOLVED |
FIXED |
2023-09-29T15:33:22Z |
1838864 |
Firmaprofesional: Failure to Respond to April 2023 Survey |
RESOLVED |
INVALID |
2023-07-14T18:26:06Z |
1838866 |
SHECA: Failure to Respond to April 2023 Survey |
RESOLVED |
FIXED |
2023-09-29T15:32:20Z |
1839105 |
SHECA: Non-compliant Subject Fields problem in OV TLS certificate |
RESOLVED |
FIXED |
2023-11-29T22:28:00Z |
1839305 |
Buypass: Domain validation method using externally operated DNS tools |
RESOLVED |
FIXED |
2024-06-30T03:26:45Z |
1841247 |
Telia: Findings in 2023 Audit |
RESOLVED |
FIXED |
2024-05-09T23:39:15Z |
1841534 |
Apple: TLS certificates issued outside the TTL of the CAA record |
RESOLVED |
FIXED |
2023-08-30T15:41:47Z |
1842121 |
Microsoft PKI Services: CRL Publication Failures |
RESOLVED |
FIXED |
2023-09-29T15:34:35Z |
1843173 |
NETLOCK: CRL Error on CRL Watch of NETLOCK DVCA CRL |
RESOLVED |
FIXED |
2023-09-29T15:33:49Z |
1843265 |
PKIoverheid: Delayed audit statements for intermediate CAs |
RESOLVED |
FIXED |
2024-03-27T16:06:27Z |
1843268 |
NAVER Cloud Trust Services: OV certificate issued with OU field |
RESOLVED |
FIXED |
2024-05-09T23:31:05Z |
1843676 |
Apple: Revocation Delay for TLS certificates issued outside the TTL of the CAA record |
RESOLVED |
FIXED |
2023-09-22T22:43:52Z |
1844514 |
MICROSEC: Incident report - No OCSP status response for 2 Precertificates |
RESOLVED |
FIXED |
2024-03-13T12:35:39Z |
1844799 |
SHECA: Failure to Submit Annual CCADB Self Assessment |
RESOLVED |
FIXED |
2023-10-12T10:23:09Z |
1845269 |
NAVER Cloud Trust Services: commonName not in SAN |
RESOLVED |
FIXED |
2023-09-29T15:35:46Z |
1845634 |
DigiCert: TLS certificates with incorrect policy OID |
RESOLVED |
FIXED |
2023-09-02T17:59:16Z |
1845803 |
GlobalSign: Three (3) revoked precertificates with reasonCode “certificateHold” |
RESOLVED |
FIXED |
2023-09-08T20:17:16Z |
1846216 |
Disig: Failure to Respond to Jun 2023 Apple Root Program Survey |
RESOLVED |
FIXED |
2023-09-29T15:34:20Z |
1846784 |
DigiCert: Delayed revocation of IV certificates |
RESOLVED |
FIXED |
2023-09-02T17:58:57Z |
1847193 |
KAMU SM: commonName not in SAN |
RESOLVED |
FIXED |
2023-09-29T15:36:29Z |
1848240 |
TWCA: Undisclosed CA |
RESOLVED |
FIXED |
2023-11-02T16:08:00Z |
1848279 |
Microsoft PKI Services: Trusted Role Control Failure |
RESOLVED |
FIXED |
2023-10-12T10:25:15Z |
1848280 |
Microsoft PKI Services: 3-Month Access Review Process Failure |
RESOLVED |
FIXED |
2023-10-12T10:24:57Z |
1848306 |
TWCA: CA certificate without EKU |
RESOLVED |
FIXED |
2023-11-02T16:08:16Z |
1848854 |
SwissSign: S/MIME LCP: CN with values other than email address |
RESOLVED |
FIXED |
2024-03-27T16:05:42Z |
1849364 |
SwissSign: Missed revocation and opening Bugzilla |
RESOLVED |
FIXED |
2023-09-22T22:44:45Z |
1850091 |
GlobalSign: EV TLS certificate with only metadata in JOI State field |
RESOLVED |
FIXED |
2023-10-12T10:48:35Z |
1850171 |
SSL.com: S/MIME certificates issued prior to validation |
RESOLVED |
FIXED |
2023-09-29T15:36:14Z |
1850807 |
IdenTrust: basicConstraints not flagged "Critical" Per Certification Practices Statement |
RESOLVED |
FIXED |
2023-09-29T15:35:19Z |
1851164 |
SwissSign: S/MIME wrong key Usage |
RESOLVED |
FIXED |
2023-09-22T22:43:36Z |
1851710 |
IdenTrust: Delay beyond 5 days in revoking misissued certificates |
RESOLVED |
FIXED |
2024-01-04T20:52:39Z |
1852404 |
CommScope: Empty SCT extensions in certificates |
RESOLVED |
FIXED |
2024-07-01T21:10:48Z |
1853447 |
IdenTrust: Temporarily Expired CRLs |
RESOLVED |
FIXED |
2023-10-12T10:26:30Z |
1853463 |
DigiCert: SMIME certificates issued inconsistent with BR’s |
RESOLVED |
FIXED |
2023-10-12T10:22:54Z |
1853663 |
Asseco DS / Certum: SMIME certificates with wrong organizationIdentifier |
RESOLVED |
FIXED |
2024-05-09T20:57:33Z |
1853783 |
IdenTrust: S/MIME certificates issued in violation of New S/MIME Baseline Requirements v1.0 |
RESOLVED |
FIXED |
2025-03-20T05:59:40Z |
1853987 |
Sectigo: S/MIME certificates with (null) string value in subject attributes |
RESOLVED |
FIXED |
2023-10-12T10:22:14Z |
1854465 |
IdenTrust: Expired ICAs CRLs |
RESOLVED |
FIXED |
2023-11-02T16:07:11Z |
1855997 |
SHECA: CRLs unavailable, not downloading |
RESOLVED |
FIXED |
2024-06-30T18:43:35Z |
1856503 |
SHECA: Failure to revoke within 5 days |
RESOLVED |
FIXED |
2023-10-19T15:38:33Z |
1856591 |
Telia: S/MIME certificates issued in violation of S/MIME BR v1.0.1 |
RESOLVED |
FIXED |
2024-01-26T17:08:50Z |
1858965 |
VikingCloud: Incorrect OCSP Response |
RESOLVED |
FIXED |
2024-01-10T19:43:33Z |
1859314 |
Telia: TLS certificates issued in violation of TLS BR v2.0.1 |
RESOLVED |
FIXED |
2024-01-26T17:08:38Z |
1859694 |
SHECA: Issuance of test certificates |
RESOLVED |
FIXED |
2023-11-29T22:25:52Z |
1859812 |
CommScope: Certificate not revoked as it was supposed to be |
RESOLVED |
FIXED |
2024-03-06T17:27:48Z |
1860299 |
Sectigo: SMIME issuance with insufficient validation of mailbox authorization or control |
RESOLVED |
FIXED |
2023-12-02T18:40:52Z |
1860697 |
DigiCert: Certificates issued inconsistent with S/MIME BR v1.0.1 |
RESOLVED |
FIXED |
2024-01-04T20:53:23Z |
1860750 |
SwissSign: EV code in JurisdiktionStateOrProvinceName |
RESOLVED |
FIXED |
2023-11-08T16:29:05Z |
1861069 |
D-Trust: Issuance of 15 DV certificates containing ‘serialNumber’ field within subject |
RESOLVED |
FIXED |
2024-06-01T14:02:33Z |
1861682 |
SwissSign: EV delayed revocation |
RESOLVED |
FIXED |
2023-12-02T18:41:24Z |
1862004 |
e-commerce monitoring GmbH: Delayed revocation |
RESOLVED |
WONTFIX |
2024-07-09T16:38:25Z |
1862082 |
D-Trust: Delay beyond 5 days in revoking misissued certificate |
RESOLVED |
FIXED |
2023-12-14T18:12:13Z |
1863122 |
CFCA: CRL Error |
RESOLVED |
FIXED |
2024-01-10T19:43:49Z |
1864204 |
Buypass: TLS certificates with incorrect Subject attribute order |
RESOLVED |
FIXED |
2024-05-10T20:23:48Z |
1865080 |
Asseco DS / Certum: TLS EV certificates with incorrect Subject attribute order |
RESOLVED |
FIXED |
2024-01-04T20:53:40Z |
1865235 |
DigiCert: Late background refreshment check |
RESOLVED |
FIXED |
2023-12-07T18:27:57Z |
1865368 |
Buypass: TLS certificates not revoked within 5 days |
RESOLVED |
FIXED |
2024-04-06T02:31:06Z |
1865880 |
Microsec: Findings in 2023 Audit |
RESOLVED |
FIXED |
2024-02-14T21:24:46Z |
1866091 |
SwissSign: EV JurisdictionStateOrProvinceName - one certificate not selected for revocation |
RESOLVED |
FIXED |
2023-12-11T16:50:53Z |
1866448 |
NAVER Cloud Trust Services: DV Certificate issued with improperly validated |
RESOLVED |
FIXED |
2024-02-14T21:28:36Z |
1866806 |
GlobalSign: S/MIME Sponsor validated certificates with CommonName value equal to OrganizationName |
RESOLVED |
FIXED |
2024-02-01T22:07:54Z |
1867130 |
Entrust: Jurisdiction Locality Wrong in EV Certificate |
RESOLVED |
FIXED |
2024-05-10T15:42:20Z |
1867851 |
SSL.com: Findings in 2023 audit |
RESOLVED |
FIXED |
2024-04-24T07:20:43Z |
1869056 |
Sectigo: Inadequate vulnerability scanning and patching |
RESOLVED |
FIXED |
2024-02-02T15:02:27Z |
1870276 |
GlobalSign: TLS OV Certificate containing unverified information |
RESOLVED |
FIXED |
2024-01-24T17:37:06Z |
1870402 |
IdenTrust: Expired CRL served |
RESOLVED |
FIXED |
2024-06-30T18:38:39Z |
1871113 |
SSL.com: Issuance of one Sponsored-Validated S/MIME certificate with organization information in givenName and surName of the subjectDN |
RESOLVED |
FIXED |
2024-05-15T14:13:55Z |
1871393 |
Asseco DS / Certum: Delayed revocation of EV certificates |
RESOLVED |
FIXED |
2024-05-09T20:57:24Z |
1872371 |
Buypass: Using an external DNS Resolver for DNS lookups |
RESOLVED |
FIXED |
2024-08-07T14:01:52Z |
1872374 |
HARICA: subject:organizationIdentifier using VATEL as a prefix for tax identifier |
RESOLVED |
FIXED |
2024-01-24T17:37:24Z |
1872738 |
Buypass: Delayed revocation of TLS certificates |
RESOLVED |
FIXED |
2025-02-14T17:04:21Z |
1873739 |
Google Trust Services: uses "DNSSec-mostly" and DTPs for DNS resolution |
RESOLVED |
INVALID |
2024-02-09T18:18:32Z |
1874196 |
SwissSign: difference in upper and lower case between CN field and SAN |
RESOLVED |
FIXED |
2024-03-27T16:05:58Z |
1875205 |
Digicert: SMIME certs missing State in Org ID |
RESOLVED |
FIXED |
2024-01-26T17:08:25Z |
1875440 |
Buypass: Findings in 2023 audit |
RESOLVED |
FIXED |
2024-03-15T16:07:21Z |
1875820 |
Telekom Security: TLS certificates with basicConstraints not marked as critical |
RESOLVED |
FIXED |
2024-08-03T09:37:19Z |
1875942 |
FNMT: Certificates issued included Policy qualifiers other than id-qt-cps |
RESOLVED |
FIXED |
2024-08-28T21:35:31Z |
1876565 |
Izenpe: Not allowed Qualifier ID OID on Certificate Policies extension |
RESOLVED |
FIXED |
2024-04-06T02:31:35Z |
1876593 |
Google Trust Services: Failure to properly validate IP address |
RESOLVED |
FIXED |
2024-06-06T05:12:12Z |
1876771 |
SwissSign: modified fields were not saved into certificates and resulted in miss-issuance |
RESOLVED |
FIXED |
2024-02-08T16:08:57Z |
1876775 |
Sectigo: Wrong usage of LEI records for the issuance of SMIME Certificates |
RESOLVED |
FIXED |
2024-03-04T16:59:22Z |
1876871 |
IdenTrust: test certificates inadvertently published in production environment |
RESOLVED |
FIXED |
2024-06-30T19:21:55Z |
1877388 |
Telekom Security: Revocation delay for TLS certificates with basicConstraints not marked as critical |
RESOLVED |
FIXED |
2025-03-14T16:58:34Z |
1877680 |
Telia: Findings in Audit 2023 |
RESOLVED |
FIXED |
2024-07-15T14:40:49Z |
1878106 |
HARICA: Anomaly in OCSP services after CA software upgrade |
RESOLVED |
FIXED |
2024-03-08T15:19:58Z |
1878139 |
Sectigo: Failure to invalidate Email DCV Random Values after 30 days |
RESOLVED |
FIXED |
2024-05-20T04:11:27Z |
1879529 |
D-Trust: "unknown" OCSP response for issued certificates |
RESOLVED |
FIXED |
2024-04-06T02:31:59Z |
1879552 |
Microsoft PKI Services: OCSP Responder does not know a Certificate |
RESOLVED |
FIXED |
2024-03-29T15:03:07Z |
1879602 |
Entrust: OCSP response signed with SHA-1 |
RESOLVED |
FIXED |
2024-07-19T17:47:10Z |
1879845 |
Asseco DS / Certum: S/MIME certificates with error in subjectAlternativeName |
RESOLVED |
FIXED |
2024-10-02T21:56:44Z |
1881364 |
Digicert: SMIME certificate with unvalidated information |
RESOLVED |
FIXED |
2024-03-29T15:03:24Z |
1882256 |
AGCE: Non-Compliant VPN Certificate Issuance |
RESOLVED |
FIXED |
2024-08-28T21:31:32Z |
1882904 |
Google Trust Services: Incorrect OCSP responses for new ICAs under test |
RESOLVED |
FIXED |
2025-02-12T06:37:46Z |
1883416 |
Certigna: TLS certificates with Basic constraint non-critical |
RESOLVED |
FIXED |
2024-08-28T21:37:52Z |
1883493 |
Izenpe: Failure to Submit Annual CCADB Self-Assessment |
RESOLVED |
FIXED |
2025-02-19T18:15:34Z |
1883620 |
TWCA: TLS EV certificates with invalid subject attribute order |
RESOLVED |
FIXED |
2024-07-03T13:28:19Z |
1883711 |
e-commerce monitoring gmbh: precertificate validity does not match leaf certificate |
RESOLVED |
WONTFIX |
2024-07-09T16:39:27Z |
1883731 |
Actalis: Certificates issued with invalid RDN order |
RESOLVED |
FIXED |
2024-06-28T19:01:00Z |
1883779 |
VikingCloud: OV Precertificates with incorrect Subject RDN encoding order |
RESOLVED |
FIXED |
2024-06-05T21:27:22Z |
1883792 |
IdenTrust: Temporary Errors in Test Website Certificates |
RESOLVED |
FIXED |
2024-06-30T19:12:54Z |
1883843 |
Entrust: EV TLS Certificate cPSuri missing |
RESOLVED |
FIXED |
2024-08-13T17:19:59Z |
1884461 |
Microsoft PKI Services: CA Certificates not published in DER Encoded Format |
RESOLVED |
FIXED |
2024-05-20T04:13:20Z |
1884532 |
ACCV: Certificates issued with cRLIssuer in CDP extension |
RESOLVED |
FIXED |
2024-07-11T15:02:17Z |
1884568 |
TWCA: Revocation delay for EV TLS certificates with invalid subject attribute order |
RESOLVED |
FIXED |
2025-02-14T17:03:36Z |
1884714 |
D-Trust: LDAP-URL in Subscriber Certificate Authority Information Access field |
RESOLVED |
FIXED |
2024-09-13T16:34:26Z |
1885132 |
TWCA: TLS certificates with non-critical basicConstraints |
RESOLVED |
FIXED |
2024-07-12T06:03:45Z |
1885754 |
Entrust: CPR was not responded to in 24 hours |
RESOLVED |
FIXED |
2024-09-13T16:33:42Z |
1886110 |
TWCA: Revocation delay for TLS certificates with non-critical basicConstraints |
RESOLVED |
FIXED |
2025-02-14T17:03:21Z |
1886135 |
CFCA: certificate basicConstraints extension not marked as critical |
RESOLVED |
FIXED |
2024-09-26T18:19:38Z |
1886257 |
Microsec: Misissuance an EV TLS certificate without CPSuri |
RESOLVED |
FIXED |
2024-08-28T21:32:32Z |
1886406 |
Hongkong Post: TLS certificates with Certificate Policies extension that does not assert http scheme |
RESOLVED |
FIXED |
2024-08-28T21:36:09Z |
1886442 |
Certigna: Revocation delay for TLS certificates with basic constraint not marked as critical |
RESOLVED |
FIXED |
2024-06-01T14:07:36Z |
1886467 |
Entrust: clientAuth TLS Certificates without serverAuth EKU |
RESOLVED |
FIXED |
2024-06-28T19:01:40Z |
1886532 |
Entrust: Delayed revocation of EV TLS certificates with missing cPSuri |
RESOLVED |
FIXED |
2025-02-21T16:30:45Z |
1886624 |
certSIGN: Certificates with incorrect Subject attribute order |
RESOLVED |
FIXED |
2024-06-05T21:29:16Z |
1886626 |
certSIGN: Delayed response to CPR |
RESOLVED |
FIXED |
2024-06-01T14:06:21Z |
1886627 |
certSIGN: Delayed revocation |
RESOLVED |
FIXED |
2024-06-01T14:05:46Z |
1886665 |
Hongkong Post: Delayed revocation of TLS certificates with Certificate Policies extension problem |
RESOLVED |
FIXED |
2025-02-28T15:36:47Z |
1886722 |
Hongkong Post: Delayed response to CPR |
RESOLVED |
FIXED |
2024-08-28T21:36:57Z |
1886785 |
ACCV: Delayed response to CPR |
RESOLVED |
FIXED |
2024-07-11T15:01:59Z |
1886788 |
ACCV: Delayed revocation of TLS certificates affected by bug #1884532 |
RESOLVED |
FIXED |
2024-06-01T14:06:45Z |
1886876 |
Let's Encrypt: keyCompromise key blocking deviation from CP/CPS |
RESOLVED |
FIXED |
2024-04-17T17:38:31Z |
1886998 |
Microsec: Late response to a CPR |
RESOLVED |
FIXED |
2024-08-28T21:32:49Z |
1887008 |
Hongkong Post: TLS certificates with basicConstraints not marked as critical |
RESOLVED |
FIXED |
2024-08-28T21:35:55Z |
1887096 |
Chunghwa Telecom: Wrong Extended Key Usage setting by GTLSCA |
RESOLVED |
FIXED |
2024-09-06T15:13:15Z |
1887110 |
Microsec: Delayed revocation of the misissued certificates |
RESOLVED |
FIXED |
2025-02-14T17:04:41Z |
1887705 |
Entrust: Delayed revocation of clientAuth TLS Certificates without serverAuth EKU |
RESOLVED |
FIXED |
2024-09-12T12:19:27Z |
1887753 |
Entrust: Delay in Updating CPS |
RESOLVED |
FIXED |
2024-07-12T16:30:01Z |
1887888 |
Hongkong Post: Delayed revocation of TLS certificates with basicConstraints not marked as critical |
RESOLVED |
FIXED |
2025-02-28T15:37:04Z |
1887941 |
Actalis: revocation delay for certificates issued with invalid RDN Order |
RESOLVED |
FIXED |
2024-06-01T14:07:09Z |
1888016 |
Digicert: Failure to include CPS URI in 1 certificate |
RESOLVED |
FIXED |
2024-06-05T21:36:18Z |
1888060 |
GDCA: Issuance of SSL/TLS certificates with Non-critical Basic Constraints |
RESOLVED |
FIXED |
2025-03-05T18:51:43Z |
1888104 |
Disig: TLS certificate with basicConstraints not marked as critical |
RESOLVED |
FIXED |
2024-07-11T15:03:49Z |
1888371 |
e-commerce monitoring GmbH: CRLs with mismatched issuer |
RESOLVED |
WONTFIX |
2024-07-09T16:38:42Z |
1888667 |
VikingCloud: Delayed preliminary report of CPR to affected Subscribers |
RESOLVED |
FIXED |
2024-06-05T21:27:01Z |
1888689 |
Asseco DS / Certum: CRL non-conformance with the TLS BRs |
RESOLVED |
FIXED |
2024-10-02T21:56:18Z |
1888714 |
Entrust: EV Certificate missing Issuer’s EV Policy OID |
RESOLVED |
FIXED |
2024-07-11T15:03:29Z |
1888881 |
CFCA: Failure to respond to a CPR in a complete and/or timely manner |
RESOLVED |
FIXED |
2025-04-03T01:34:35Z |
1888882 |
CFCA: Delayed revocation of TLS certificates(basicConstraints extension not marked as critical) |
RESOLVED |
FIXED |
2025-03-27T03:23:12Z |
1889062 |
GDCA: Delayed revocation of SSL/TLS certificates with Non-critical Basic Constraints |
RESOLVED |
FIXED |
2025-04-03T01:36:07Z |
1889217 |
Entrust: CRL non-conformance with the TLS BRs |
RESOLVED |
FIXED |
2024-07-01T15:09:09Z |
1889420 |
Firmaprofesional: Policy Qualifiers other than id-qt-cps present for certificate |
RESOLVED |
FIXED |
2024-09-04T16:07:42Z |
1889567 |
ACCV: Certificates issued with Policy qualifiers other than id-qt-cps |
RESOLVED |
FIXED |
2024-08-28T21:35:12Z |
1889570 |
NETLOCK: Policy Qualifiers other than id-qt-cps is included in TLS certificates |
RESOLVED |
FIXED |
2024-08-28T21:32:12Z |
1889672 |
Disig: Certificates with incorrect Subject attribute order |
RESOLVED |
FIXED |
2024-06-01T14:10:18Z |
1889699 |
Microsec: Disallowed subject attribute field in DV certificate |
RESOLVED |
FIXED |
2024-08-28T21:34:58Z |
1890123 |
Entrust: Failed to provide a preliminary incident report according to TLS BR 4.9.5 |
RESOLVED |
FIXED |
2024-08-13T17:20:21Z |
1890685 |
Entrust: Failure to revoke EV TLS certificates issued before CPS update |
RESOLVED |
FIXED |
2025-02-21T16:31:14Z |
1890896 |
Entrust: CPS typographical (text placement) error |
RESOLVED |
FIXED |
2024-08-15T13:35:16Z |
1890898 |
Entrust: Failure to revoke OV TLS - CPS typographical (text placement) error |
RESOLVED |
FIXED |
2024-07-28T14:39:21Z |
1890901 |
Entrust: Delayed incident report - CPS typographical (text placement) error |
RESOLVED |
FIXED |
2024-05-05T19:36:31Z |
1891039 |
Sectigo: Premature disabling of CRL generation for an inactive CA |
RESOLVED |
FIXED |
2024-05-05T19:21:42Z |
1891225 |
D-Trust: Issuance of 15 certificates with incorrect subject attribute order |
RESOLVED |
FIXED |
2024-08-07T14:23:15Z |
1891245 |
Sectigo: EV Certificate issuance with incorrect subject:serialNumber attribute value |
RESOLVED |
FIXED |
2024-05-13T21:29:39Z |
1891251 |
FIRMAPROFESIONAL: Delayed leaf revocation |
RESOLVED |
FIXED |
2024-06-01T14:07:52Z |
1891331 |
NETLOCK: Policy Qualifiers other than id-qt-cps is included in TLS certificates - delayed revocation |
RESOLVED |
DUPLICATE |
2025-03-10T17:34:47Z |
1891531 |
Digicert: Government Entity listed instead of registration number |
RESOLVED |
FIXED |
2024-05-02T21:31:13Z |
1892419 |
Chunghwa Telecom: Delayed Revocation Due to GTLSCA EKU Misissuance |
RESOLVED |
FIXED |
2025-02-12T17:11:31Z |
1893546 |
e-commerce monitoring gmbh: failure to follow incident report requirements |
RESOLVED |
WONTFIX |
2024-07-09T16:38:56Z |
1893610 |
D-Trust: Notice to affected Subscriber and person filing CPR not sent within 24 hours |
RESOLVED |
FIXED |
2024-06-30T20:21:37Z |
1894054 |
SwissSign: MPKI step-up process sets wrong JoI Locality |
RESOLVED |
FIXED |
2024-07-03T13:28:01Z |
1894111 |
Entrust: Not updating CPR Problem Reporting Mechanism fields in CCADB |
RESOLVED |
FIXED |
2025-01-22T19:53:02Z |
1894560 |
DigiCert: Incorrect case in Business Category |
RESOLVED |
FIXED |
2024-07-03T13:27:34Z |
1895006 |
IdenTrust: unintended creation of a Root CA certificate |
RESOLVED |
FIXED |
2024-08-23T15:34:51Z |
1895312 |
TunTrust: CRL and OCSP unavailable |
RESOLVED |
FIXED |
2024-09-18T20:12:11Z |
1895722 |
Sectigo: Incorrect inclusion of DBA name |
RESOLVED |
FIXED |
2024-06-05T21:36:42Z |
1896053 |
Digicert: Delayed Revocation for bug 1894560 |
RESOLVED |
FIXED |
2025-05-08T17:41:10Z |
1896108 |
Telia: Certificates Issued with lower case value in subject:countryName |
RESOLVED |
FIXED |
2024-09-06T04:14:42Z |
1896190 |
D-Trust: Issuance of an EV certificate containing a mixup of the Subject's postalCode and localityName |
RESOLVED |
FIXED |
2024-11-06T17:13:35Z |
1896462 |
Digicert: Preview certificate uploaded to CCADB instead of the actual certificate |
RESOLVED |
FIXED |
2024-06-01T13:58:43Z |
1896553 |
Telia: Delayed revocation of seven (7) certificates related to incident 1896108 |
RESOLVED |
FIXED |
2025-02-12T17:10:11Z |
1896596 |
SECOM: Certificates Issued with lower case value in subject:countryName |
RESOLVED |
FIXED |
2024-07-24T19:20:50Z |
1897134 |
certSIGN: Findings in 2024 ETSI Audit - Audit Incident Report |
RESOLVED |
FIXED |
2024-09-06T15:14:19Z |
1897346 |
SECOM: Difference in upper and lower case between CN field and SAN |
RESOLVED |
FIXED |
2024-07-24T19:21:05Z |
1897457 |
e-commerce monitoring gmbh: failure to maintain links to historic CP/CPS versions |
RESOLVED |
WONTFIX |
2024-07-09T16:39:11Z |
1897538 |
Sectigo: Incorrectly included registrationStateOrProvince in PSD-based cabfOrganizationIdentifier extension |
RESOLVED |
FIXED |
2024-06-14T17:08:26Z |
1897569 |
IdenTrust: TLS ICA with User Notice in Policy Qualifier |
RESOLVED |
FIXED |
2024-08-23T15:35:08Z |
1897630 |
Entrust: Jurisdiction issue in some EV TLS & Code Signing certificates |
RESOLVED |
FIXED |
2024-08-15T13:35:41Z |
1898847 |
Entrust: Delayed reporting of Jurisdiction issue in some EV TLS & Code Signing certificates |
RESOLVED |
FIXED |
2024-08-15T13:36:14Z |
1898848 |
Entrust: Delayed revocation of certificates affected by Jurisdiction issue in some EV TLS & Code Signing certificates |
RESOLVED |
FIXED |
2025-02-21T16:31:31Z |
1898986 |
DigiCert: Incorrect Org ID Scheme in S/MIME |
RESOLVED |
FIXED |
2024-06-21T16:12:39Z |
1899466 |
Chunghwa Telecom: Controversial Values within Extension (2.5.29.9, subjectDirectoryAttributes) |
RESOLVED |
FIXED |
2024-09-13T16:35:09Z |
1900129 |
Certainly: Serving invalid or incomplete CRLs |
RESOLVED |
FIXED |
2024-06-28T19:01:22Z |
1900492 |
IdenTrust: Invalid OrganizationIdentifier in S/MIME certificates |
RESOLVED |
FIXED |
2024-06-21T16:12:22Z |
1900654 |
Certigna: ARL without reasoncode for recent revoked CA certificates |
RESOLVED |
FIXED |
2024-08-28T21:37:31Z |
1901270 |
Entrust: Action Items from June 2024 Report |
RESOLVED |
FIXED |
2025-02-03T18:06:54Z |
1901578 |
CommScope: Certificates were issued in which third-party web-based tools were used during validation. |
RESOLVED |
FIXED |
2024-07-28T14:40:05Z |
1902042 |
Siemens: meaningless characters in personal name fields |
RESOLVED |
FIXED |
2024-08-23T15:35:25Z |
1902310 |
Sectigo: Trusted Role Access provided prior to completion of onboarding process |
RESOLVED |
FIXED |
2024-07-11T15:01:31Z |
1902592 |
SHECA: EV certificate subject RDN order is incorrect |
RESOLVED |
FIXED |
2024-08-21T14:39:52Z |
1902670 |
Google Trust Services: SXG certificates issued without correctly checking CAA restrictions |
RESOLVED |
FIXED |
2024-07-31T18:31:10Z |
1902748 |
Sectigo: QWAC certificates issued with incorrect subject:organizationIdentifier attribute value |
RESOLVED |
FIXED |
2024-08-28T21:30:28Z |
1902868 |
GoDaddy: CPR was not responded to in 24 hours |
RESOLVED |
FIXED |
2024-08-21T14:40:17Z |
1902947 |
SHECA: The certificate's cpsURI is empty |
RESOLVED |
FIXED |
2024-08-21T14:39:33Z |
1903066 |
Chunghwa Telecom: Delayed Revocation with Controversial Extension (2.5.29.9, SubjectDirectoryAttributes) |
RESOLVED |
FIXED |
2025-02-12T17:12:18Z |
1903823 |
WISeKey: OCSP responding "Unauthorized" for a TLS certificate |
RESOLVED |
FIXED |
2024-07-31T18:31:26Z |
1904038 |
Chunghwa Telecom: “Test Website - Valid" URL disclosed to CCADB is expired |
RESOLVED |
FIXED |
2025-04-18T15:31:36Z |
1904257 |
Microsoft PKI Services: Invalid Email Address for CPRs |
RESOLVED |
FIXED |
2024-06-30T20:24:53Z |
1904399 |
CommScope: OCSP responses contain issuer certificate |
RESOLVED |
INVALID |
2024-08-17T07:37:59Z |
1904402 |
CommScope: Incomplete Incident Report |
RESOLVED |
FIXED |
2024-09-26T18:19:15Z |
1904494 |
Asseco DS / Certum: Cross-certificate not included in 2024 S/MIME Audit statement |
RESOLVED |
FIXED |
2024-09-04T16:05:55Z |
1904748 |
GoDaddy : CAA checks did not properly handle issuewild tag allowing FQDN SANs to be added to wildcard certs |
RESOLVED |
FIXED |
2024-10-31T14:45:17Z |
1904749 |
GoDaddy : CAA checks passed when records contained incorrect variants of godaddy.com or starfieldtech.com |
RESOLVED |
FIXED |
2024-10-31T14:45:50Z |
1905419 |
GoDaddy: Intermittent unauthorized OCSP response when certificate is freshly issued |
RESOLVED |
FIXED |
2024-10-31T14:45:36Z |
1905446 |
IdenTrust: Unauthorized OCSP response on a Timestamp certificate |
RESOLVED |
FIXED |
2024-12-09T14:15:59Z |
1905509 |
NETLOCK: CPR was not responded to in 24 hours |
RESOLVED |
FIXED |
2025-05-08T17:52:46Z |
1906028 |
Microsoft PKI Services: Vulnerability Management Exception Tracking |
RESOLVED |
FIXED |
2024-08-15T13:37:01Z |
1906115 |
Netlock: Delayed reply from CPR sent to contact listed in section 1.5.2 of CP/S |
RESOLVED |
FIXED |
2024-08-28T21:31:54Z |
1906467 |
Entrust: S/MIME mailbox address not in subjectAltName |
RESOLVED |
FIXED |
2025-05-13T20:14:23Z |
1906470 |
Entrust: S/MIME mailbox address case mismatch between subject and subjectAltName |
RESOLVED |
FIXED |
2025-05-13T20:14:42Z |
1906690 |
Actalis: CRL distribution point with ldap scheme |
RESOLVED |
FIXED |
2025-03-18T00:54:38Z |
1907568 |
NETLOCK: CPS 1.5.2. problem and contact information update |
RESOLVED |
FIXED |
2024-09-06T15:16:25Z |
1907667 |
Disig: Two certificates with same serial number |
RESOLVED |
FIXED |
2024-08-17T07:39:14Z |
1907833 |
Certigna: Findings in 2024 ETSI Audit – Audit Incident Report |
RESOLVED |
FIXED |
2024-08-28T21:37:11Z |
1907949 |
iTrusChina: CRL Reason Codes |
RESOLVED |
FIXED |
2024-08-28T21:30:48Z |
1908128 |
NAVER Cloud Trust Services: Certificate issued with incorrect OCSP URI in AIA |
RESOLVED |
FIXED |
2024-08-28T21:29:54Z |
1908130 |
NAVER Cloud Trust Services: Incorrect keyUsage for ECC certificate |
RESOLVED |
FIXED |
2024-08-28T21:30:09Z |
1908690 |
Sectigo: Temporary unavailability for subset of CRLs |
RESOLVED |
FIXED |
2024-08-23T15:34:34Z |
1909203 |
Asseco DS / Certum: CP/CPS, Revocation Requests Mechanism, Certificate Problem Report, CRL and OCSP disruption |
RESOLVED |
FIXED |
2025-05-13T22:48:40Z |
1909948 |
GoDaddy: Edge Case for Data Reuse Outside of Timeframes |
RESOLVED |
FIXED |
2024-10-31T14:46:04Z |
1910195 |
IdenTrust: Invalid special characters in S/MIME Certificates |
RESOLVED |
FIXED |
2024-09-06T15:14:36Z |
1910237 |
Entrust: Delayed Revocation for S/MIME certificates |
RESOLVED |
FIXED |
2025-05-13T22:52:41Z |
1910258 |
DigiCert: Typo in TLS Org Name |
RESOLVED |
FIXED |
2025-01-29T22:33:00Z |
1910322 |
DigiCert: Random value in CNAME without underscore prefix |
RESOLVED |
FIXED |
2025-02-24T21:59:12Z |
1910451 |
Sectigo: Missing character in subject:organizationName attribute value |
RESOLVED |
FIXED |
2024-08-21T14:40:40Z |
1910512 |
CommScope: Certificates not logged in CT logs as stated in CP/CPS |
RESOLVED |
FIXED |
2024-10-07T15:39:08Z |
1912225 |
Sectigo: HTML encoded characters in subject attribute values |
RESOLVED |
FIXED |
2024-09-26T18:18:59Z |
1913310 |
D-Trust: CRL-Entries without required CRL Reason Code |
RESOLVED |
FIXED |
2024-09-13T16:34:40Z |
1914020 |
SwissSign: S/MIME NCP non ASCII symbols in email and SAN field wrong coding |
RESOLVED |
FIXED |
2024-09-13T16:35:26Z |
1914023 |
SwissSign: S/MIME LCP not-permitted key usage |
RESOLVED |
FIXED |
2025-04-03T01:35:46Z |
1914065 |
Entrust: S/MIME certificates lacking OU verification |
RESOLVED |
FIXED |
2025-02-28T15:38:40Z |
1914067 |
IdenTrust: Expired CRLs |
RESOLVED |
FIXED |
2024-10-23T16:46:23Z |
1914365 |
SHECA: CRLReason code usage error |
RESOLVED |
FIXED |
2025-03-05T18:52:00Z |
1914383 |
Telekom Security: CRL-Entries with wrong CRL Reason Codes |
RESOLVED |
FIXED |
2024-12-11T20:55:23Z |
1914419 |
Actalis: Use of CRLReason Code in Certificate Revocation |
RESOLVED |
FIXED |
2025-02-04T19:22:55Z |
1914466 |
eMudhra emSign PKI Services: CA Certificates not published in DER Encoded Format |
RESOLVED |
FIXED |
2024-10-02T18:33:57Z |
1914893 |
Amazon Trust Services: CRL not DER-encoded |
RESOLVED |
FIXED |
2024-09-18T20:11:56Z |
1914911 |
DigiCert: Unclear Disclosure of CAA Issuer Domain Names |
RESOLVED |
FIXED |
2025-01-08T16:59:51Z |
1914999 |
Entrust: S/MIME OrgID Country not matching C field |
RESOLVED |
FIXED |
2025-02-28T15:38:26Z |
1915883 |
Sectigo: Missing data in cabfOrganizationIdentifier |
RESOLVED |
FIXED |
2024-09-26T18:20:01Z |
1916392 |
Chunghwa Telecom: TLS Certificates Contains two LocalityName Values in SubjectDN by GTLSCA |
RESOLVED |
FIXED |
2025-02-12T17:06:54Z |
1916478 |
eMudhra emSign PKI Services: Delayed Revocation of SSL/TLS Certificates |
RESOLVED |
FIXED |
2025-04-09T18:44:34Z |
1916489 |
SwissSign: LDAP URL still in CRL distribution point (CDP) |
RESOLVED |
FIXED |
2025-03-18T00:57:56Z |
1917046 |
NETLOCK: Findings in 2024 Audit |
RESOLVED |
FIXED |
2025-04-18T15:31:56Z |
1917224 |
Chunghwa Telecom:Delayed Annual Audit Report 2024 |
RESOLVED |
FIXED |
2024-12-05T21:11:43Z |
1917405 |
Sectigo: S/MIME OV Mis-issuance |
RESOLVED |
FIXED |
2024-10-11T17:31:37Z |
1917459 |
eMudhra emSign PKI Services : OCSP Responder Time Inconsistency |
RESOLVED |
FIXED |
2025-02-14T17:06:00Z |
1917571 |
Asseco DS / Certum: Organization Identifier and Country field discrepancies |
RESOLVED |
FIXED |
2024-11-06T17:13:18Z |
1917896 |
GlobalSign: Incorrect whois information for TLD |
RESOLVED |
FIXED |
2025-03-18T00:08:40Z |
1918380 |
Entrust: Business Entity not permitted in CPS |
RESOLVED |
FIXED |
2024-11-06T17:13:50Z |
1918427 |
D-Trust: Non-compliance of issued root and intermediate S/MIME certificates |
RESOLVED |
INVALID |
2024-10-11T17:30:42Z |
1918467 |
QuoVadis: Findings in 2024 ETSI Audit of QuoVadis Qualified Web ICA G2 |
RESOLVED |
FIXED |
2024-10-07T15:39:23Z |
1919162 |
IdenTrust: TLS Certificates with outdated certificate profile |
RESOLVED |
FIXED |
2024-12-09T14:17:06Z |
1919304 |
GlobalSign: Caching headers inaccurate for subset of CRLs |
RESOLVED |
FIXED |
2024-10-23T16:46:45Z |
1920659 |
Telia: S/MIME Certificate issued to expired domain |
RESOLVED |
FIXED |
2024-12-06T16:16:14Z |
1921254 |
Izenpe: Duplicate attribute in Subject |
RESOLVED |
FIXED |
2025-02-19T18:17:03Z |
1921387 |
Entrust: Improperly Verified Business Category |
RESOLVED |
FIXED |
2025-03-18T00:12:53Z |
1921424 |
SwissSign: Findings in 2024 Audit |
RESOLVED |
FIXED |
2024-11-04T14:58:59Z |
1921573 |
Let's Encrypt: No Meaningful Subject Distinguished Name |
RESOLVED |
FIXED |
2024-11-06T17:12:40Z |
1921596 |
KIR: Failure to disclose intermediate certificate within 7 days in ccadb |
RESOLVED |
FIXED |
2025-02-19T18:16:34Z |
1921597 |
KIR: Intermediate CA - SZAFIR Trusted CA4 - Certificate Policies extension - non-compliance |
RESOLVED |
FIXED |
2025-02-19T18:16:46Z |
1921598 |
KIR: Intermediate CA - SZAFIR Trusted CA3 - Certificate Policies extension - non-compliance |
RESOLVED |
FIXED |
2025-02-19T18:16:18Z |
1922572 |
KIR: Delayed revocation within seven (7) days for bug 1921598 |
RESOLVED |
FIXED |
2025-05-08T17:53:48Z |
1922844 |
Izenpe: Not allowed Qualifier ID OID on Certificate Policies extension of Precertificates |
RESOLVED |
FIXED |
2025-03-17T23:25:59Z |
1922906 |
FNMT: LDAP URI in CRL Distribution Points Extension |
RESOLVED |
FIXED |
2025-02-12T17:08:20Z |
1923279 |
iTrusChina: lacking 2018 KGC and GAP period audit report |
RESOLVED |
FIXED |
2025-03-17T23:52:55Z |
1924492 |
eMudhra emSign PKI Services: Failure To Update CA Owner Information In CCADB |
RESOLVED |
FIXED |
2025-02-14T17:06:16Z |
1924497 |
certSIGN: Missing certificate from the list of bad order subject attributtes |
RESOLVED |
FIXED |
2025-01-31T16:47:57Z |
1924992 |
GoDaddy: Does not provide a method for domain owners to revoke their certificates |
RESOLVED |
FIXED |
2025-04-03T01:34:03Z |
1925239 |
Microsec: Expired Certificates on test Pages for Revocation |
RESOLVED |
FIXED |
2025-01-14T18:07:12Z |
1925293 |
Firmaprofesional: Incorrect publication of information for "Test Website - Revoked" URL in the CCADB. |
RESOLVED |
FIXED |
2025-02-28T15:37:36Z |
1927384 |
iTrusChina: Issuance of certificates using keys previously reported as compromised |
RESOLVED |
FIXED |
2025-01-29T04:10:59Z |
1927506 |
DigiCert: Incorrect OrgID in S/MIME certificates for one customer |
RESOLVED |
FIXED |
2025-01-24T17:54:00Z |
1927675 |
iTrusChina: CPR was not responded to within 24 hours |
RESOLVED |
FIXED |
2024-12-02T18:08:38Z |
1930029 |
IdenTrust: Approval of TLS certificate renewal without domain validation |
RESOLVED |
FIXED |
2025-02-19T18:16:03Z |
1930759 |
DigiCert: Domain used for CRLs and OCSP has expired |
RESOLVED |
FIXED |
2025-02-12T17:10:35Z |
1931413 |
Google Trust Services: New hire onboarding deviation from written procedure |
RESOLVED |
FIXED |
2024-12-27T23:25:57Z |
1931515 |
SECOM: Issuance of TLS server certificates using keys previously compromised |
RESOLVED |
FIXED |
2025-01-06T16:04:20Z |
1931615 |
SSL.com: Entrust API and CAA checking |
RESOLVED |
DUPLICATE |
2024-12-03T15:53:22Z |
1931636 |
SSL.com: Delay in publishing OCSP responses |
RESOLVED |
FIXED |
2025-02-12T17:07:13Z |
1931683 |
eMudhra emSign PKI Services : Key Blocking Mechanism Fails to Validate Historical Public Key Reuse. |
RESOLVED |
FIXED |
2025-04-09T18:44:55Z |
1931886 |
Entrust: CRL missing revocation reasonCode |
RESOLVED |
FIXED |
2025-02-12T17:07:51Z |
1932973 |
SSL.com: CAA Empty set handling results in Wildcard issuance |
RESOLVED |
FIXED |
2025-04-07T14:51:22Z |
1932994 |
DigiCert: Some CRLs were not updated for a few days |
RESOLVED |
FIXED |
2025-02-12T17:10:53Z |
1933353 |
IdenTrust: Incorrect response for OCSP validation |
RESOLVED |
FIXED |
2025-03-21T13:36:44Z |
1934361 |
ICP-Brasil: Mis-issued certificate |
RESOLVED |
FIXED |
2025-02-14T17:06:33Z |
1934790 |
GlobalSign: OV TLS certificate with incorrect countryName value for organization |
RESOLVED |
FIXED |
2025-01-14T18:06:54Z |
1935393 |
Asseco DS / Certum: Failure to Update Policy Documents within 365 Days |
RESOLVED |
FIXED |
2025-01-29T04:04:55Z |
1936741 |
Telia: Findings in 2024 Audit |
RESOLVED |
FIXED |
2024-12-20T18:03:11Z |
1936906 |
DigiCert: Invalid Characters in S/MIME Subject Fields |
RESOLVED |
FIXED |
2025-02-14T17:02:52Z |
1936908 |
DigiCert: Encoded HTML entities in attribute values |
RESOLVED |
FIXED |
2025-03-18T00:00:46Z |
1937210 |
DigiCert: Late incident report for bug 1925106 |
RESOLVED |
FIXED |
2025-02-28T15:39:26Z |
1938236 |
SSL.com: Failure to process CAA records from one SubCA |
RESOLVED |
FIXED |
2025-02-28T15:37:52Z |
1939809 |
D-Trust: QCStatement with http link of PKI Disclosure Statements |
RESOLVED |
FIXED |
2025-03-21T13:36:22Z |
1941009 |
eMudhra emSign PKI Services : Issue with revocation as part of automated reissuance |
RESOLVED |
FIXED |
2025-04-09T18:44:16Z |
1942130 |
HARICA: S/MIME certificate issuance without proper validation |
RESOLVED |
FIXED |
2025-05-01T14:09:59Z |
1942241 |
GoDaddy: Revocation process is unusable due to contact address not accepting attachments |
RESOLVED |
FIXED |
2025-05-13T20:15:24Z |
1942270 |
SSL.com: Revocation process requires submission to a form that is unusable |
RESOLVED |
INVALID |
2025-04-07T14:51:39Z |
1942651 |
Sectigo / SSL.com: Late disclosure of updated SSL.com CP/CPS to CCADB |
RESOLVED |
FIXED |
2025-02-14T17:04:56Z |
1942877 |
GoDaddy: Delayed revocation |
RESOLVED |
FIXED |
2025-05-08T17:43:23Z |
1942879 |
Globalsign: Delayed revocation |
RESOLVED |
FIXED |
2025-02-12T17:09:07Z |
1943379 |
Actalis: CRL with duplicate serial number in revokedCertificates |
RESOLVED |
FIXED |
2025-05-08T17:50:46Z |
1943528 |
Entrust: delayed revocation |
RESOLVED |
FIXED |
2025-02-19T18:15:49Z |
1943596 |
HARICA: S/MIME certificate issuance with incorrect commonName |
RESOLVED |
FIXED |
2025-05-01T14:10:12Z |
1943604 |
HARICA: TLS Server certificate issuance without proper validation |
RESOLVED |
FIXED |
2025-05-25T18:26:59Z |
1944436 |
Microsoft PKI Services: Subject Key Identifiers in Some Subscriber Certificates Do Not Comply with RFC 5280 |
RESOLVED |
FIXED |
2025-04-03T01:35:02Z |
1944815 |
GlobalSign: Organization-validated SMIME certificate with invalid organizationIdentifier for European country |
RESOLVED |
FIXED |
2025-02-26T15:51:30Z |
1945197 |
Sectigo: Late receipt and disclosure to CCADB of ETSI audit letters |
RESOLVED |
FIXED |
2025-02-28T15:37:21Z |
1945389 |
HARICA: delayed revocation for bug 1943596 |
RESOLVED |
FIXED |
2025-05-01T14:09:37Z |
1945409 |
CommScope: Service outage |
RESOLVED |
FIXED |
2025-05-16T23:01:04Z |
1945867 |
Izenpe: Incorrect Unicode characters in Subject |
RESOLVED |
FIXED |
2025-04-18T15:32:11Z |
1946414 |
Chunghwa Telecom: Failure to Submit Annual CCADB Self-Assessment 2023 by GTLSCA. |
RESOLVED |
FIXED |
2025-04-09T18:45:17Z |
1946418 |
Chunghwa Telecom: Delayed to Submit Annual CCADB Self-Assessment 2024 by GTLSCA. |
RESOLVED |
FIXED |
2025-03-14T16:57:56Z |
1946921 |
SHECA: DV SSL certificate format is abnormal |
RESOLVED |
FIXED |
2025-04-09T18:43:30Z |
1946927 |
Sectigo: Intermittent OCSP unauthorized responses for certificates older than 15 minutes |
RESOLVED |
FIXED |
2025-05-16T22:58:55Z |
1947034 |
Chunghwa Telecom: outdated and stale policy documents disclosed to the CCADB |
RESOLVED |
FIXED |
2025-04-11T16:00:02Z |
1947207 |
FNMT: Incorrect publication of information for Test Website - Valid |
RESOLVED |
FIXED |
2025-02-28T15:38:56Z |
1948368 |
Google Trust Services: Self-audit tooling MPIC perspective verification inconsistency |
RESOLVED |
FIXED |
2025-03-14T16:57:30Z |
1949131 |
CFCA: BasicConstraints are not marked as critical certificates are missing and therefore not revoked |
RESOLVED |
FIXED |
2025-05-08T17:54:44Z |
1949203 |
Actalis: two CAs with the same CRLDP |
RESOLVED |
FIXED |
2025-04-03T01:35:21Z |
1949755 |
WISeKey: S/MIME certificate issuance without proper validation |
RESOLVED |
FIXED |
2025-04-11T15:59:46Z |
1949895 |
GoDaddy: Delayed CRL File Updates |
RESOLVED |
FIXED |
2025-05-13T20:13:16Z |
1951415 |
Chunghwa Telecom: Failure to check restrictive CAA record during Migration |
RESOLVED |
FIXED |
2025-05-08T17:53:09Z |
1952519 |
Microsec: Inconsistent Disclosure of S/MIME BR Audit Information in CCADB |
RESOLVED |
FIXED |
2025-05-08T17:51:44Z |
1952591 |
CommScope: Validation issue in SCT extensions in certificates |
RESOLVED |
FIXED |
2025-05-16T22:59:19Z |
1952639 |
TWCA: Missing or Inconsistent Disclosure of S/MIME BR Audits |
RESOLVED |
FIXED |
2025-05-25T18:27:21Z |
1954580 |
Sectigo: Temporary failure to publish OCSP responses for newly issued certificates |
RESOLVED |
FIXED |
2025-05-16T22:59:56Z |
1954861 |
Let's Encrypt: Early CRL Removal Incident |
RESOLVED |
FIXED |
2025-04-09T18:43:07Z |
1954889 |
Certainly: Early CRL Entry Removal |
RESOLVED |
INVALID |
2025-03-28T04:35:29Z |
1955365 |
Apple: Public Key Reuse |
RESOLVED |
FIXED |
2025-05-19T14:26:13Z |
1955799 |
CFCA: Failed to follow Report lifecycle rule to respond within 7 days |
RESOLVED |
FIXED |
2025-04-11T16:00:26Z |
1956681 |
Entrust: Cross-certified CA CP/CPS not updated in CCADB |
RESOLVED |
FIXED |
2025-05-08T17:51:16Z |
1956910 |
Chunghwa Telecom: OV TLS Server certificate issuance by GTLSCA without proper validation |
RESOLVED |
FIXED |
2025-05-22T14:41:43Z |
1957962 |
Telekom Security: QCStatement with http link to PDS |
RESOLVED |
FIXED |
2025-05-22T14:42:14Z |
1963546 |
certSIGN: Findings in 2025 ETSI Audit - Audit Incident Report |
RESOLVED |
FIXED |
2025-05-19T20:10:50Z |