Bugzilla Mozilla



  1. Mozilla Bugzilla Skin
  2. Bugzilla.mozilla.org
  3. Bugzilla Log In
  4. Bugzilla Mozilla Download
  5. Firefox Bug Tracker
Bugzilla Mozilla
< CA

Bugzilla is a web -based general-purpose bug tracking system and testing tool originally developed and used by the Mozilla project, and licensed under the Mozilla Public License. Welcome to Bugzilla. Documentation; Advanced Search; New Bug; New Account; Quick Search help Install the Quick Search plugin Bugzilla Etiquette.

  • 1Open CA Bugs in Bugzilla
  • 2Closed CA Bugs

Open CA Compliance Bugs

A CA compliance bug relates to a concern about a CA's certificates failing to comply with Mozilla's CA Certificate Policy and/or the CA/Browser Forum's Baseline Requirements, and is determined to not be an imminent security concern. A CA's response to CA compliance bug includes providing an Incident Report in the bug.

Anyone may create a CA Compliance bug as follows:

Mozilla Bugzilla Skin

  • Whiteboard = [ca-compliance]
    • If the issue is due to mandated restrictions regarding COVID-19, use Whiteboard = [ca-compliance][covid-19]

Bugzilla.mozilla.org

Full Query
IDSummaryStatusAssigned toWhiteboardLast change time
1632632Buypass: Illegal Business Category in a PSD2 QWACASSIGNEDMads Henriksveen[ca-compliance] Next update 2021-06-202021-04-02T17:43:21Z
1647468D-TRUST: Wrong key usage (Key Encipherment)ASSIGNEDEnrico Entschew[ca-compliance]2021-04-19T16:12:45Z
1649937GlobalSign: Incorrect OCSP Delegated Responder CertificateASSIGNEDdouglas.beattie[ca-compliance] Next Update 2021-04-232021-04-19T16:17:45Z
1652581Google Trust Services digitalSignature KeyUsage not setASSIGNEDAndy Warner[ca-compliance]2021-04-09T16:45:02Z
1658792Entrust: Invalid data in State/Province FieldASSIGNEDDathan Demone[ca-compliance] Next Update 2021-04-012021-04-15T21:07:04Z
1663953TunTrust : OCSP unreachableASSIGNEDAgence Nationale de Certification Electronique[ca-compliance] Next Update 2021-06-152021-04-08T15:27:17Z
1670337Microsoft PKI Services: Certificate Mis-Issuance, DNSNames must have a valid TLDASSIGNEDJohn Mason[ca-compliance] Next Update 2021-04-192021-04-20T03:50:51Z
1674561Microsoft: DV certificate issued with OV fieldsASSIGNEDDustin Hollenback[ca-compliance] Next update 2021-05-012021-04-02T17:56:26Z
1676352Microsec e-Szigno: Certificate validity period greater than 398 daysASSIGNEDdr. Sándor SZŐKE[ca-compliance] Next update 2021-05-012021-04-23T17:47:25Z
1677737SwissSign: duplicate serial numberASSIGNEDMike Guenther[ca-compliance]2021-04-08T11:51:44Z
1680378Netlock: Replacement of enduser certificates after the EVGL 1.7.4 self-auditASSIGNEDVarga Viktor[ca-compliance]2021-04-22T14:27:34Z
1685370Entrust: Incorrect Business Category Value Discovered in an EV SSL CertificateASSIGNEDDathan Demone[ca-compliance]2021-04-16T19:36:52Z
1690807GlobalSign: RSA-1024 leaf certificate issued after 2013-12-31ASSIGNEDEva Van Steenberge[ca-compliance]2021-04-06T06:05:10Z
1693930Microsoft PKI Services: Policy Documentation, Failure to update Subscriber Certificate Max Validity PeriodASSIGNEDJohn Mason[ca-compliance]2021-03-04T22:04:27Z
1695786SECOM: Unqualified domain name in SANASSIGNEDHisashi Kamo[ca-compliance]2021-04-22T13:46:21Z
1695938SECOM: FUJIFILM intermediate not listed in audit statementASSIGNEDHisashi Kamo[ca-compliance]2021-04-22T13:20:58Z
1696227Entrust - Incorrect Jurisdiction Country Value in an EV CertificateASSIGNEDDathan Demone[ca-compliance] Next update 2021-06-012021-04-16T19:36:40Z
1700145Firmaprofesional: incorrect reserved CA/B Forum OIDs in certificatesASSIGNEDchemalogo[ca-compliance]2021-04-22T17:20:17Z
1700809Microsoft PKI Services: Failure to disclose Unconstrained Intermediate within 7 DaysASSIGNEDJohn Mason[ca-compliance]2021-04-14T22:42:25Z
1703528Telekom Security: Key Encipherment in two ECC SAN TLS certificatesASSIGNEDArnold Essing[ca-compliance]2021-04-21T15:49:26Z
1704140Camerfirma: Govern d'Andorra Audit DelayASSIGNEDAna Lopes[ca-compliance] [audit-delay] 2021-04-23T11:36:14Z
1704199FNMT: Minor non-conformities in 2021 audit statementASSIGNEDBrox[ca-compliance]2021-04-12T09:34:40Z
1705187KIR S.A.: CN domain not in SANASSIGNEDPiotr Grabowski[ca-compliance]2021-04-19T18:49:18Z
1705337KIR S.A.: Invalid localityName + CRL Revoked but OCSP UnknownASSIGNEDPiotr Grabowski[ca-compliance]2021-04-15T20:27:48Z
1705419Microsoft: Underscore in SANASSIGNEDJohn Mason[ca-compliance]2021-04-24T16:09:55Z
1705480SECOM: CP/CPS does not clearly specify domain validation methodsASSIGNEDHisashi Kamo[ca-compliance]2021-04-23T13:19:01Z
1705647KIR S.A.: Invalid organizationNameASSIGNEDPiotr Grabowski[ca-compliance]2021-04-21T08:35:05Z
1705657KIR S.A.: Many certificates with OCSP UnknownASSIGNEDPiotr Grabowski[ca-compliance]2021-04-21T15:42:21Z
1705791Telekom Security: Multiple commonName in certificatesASSIGNEDArnold Essing[ca-compliance]2021-04-23T08:41:20Z
1705832KIR S.A.: DV certificates with locality name, organization name and stateOrProvinceNameASSIGNEDPiotr Grabowski[ca-compliance]2021-04-20T16:54:00Z
1705904KIR S.A.: CP/CPS contains noncompliant DV method, does not specify CAA domainsASSIGNEDPiotr Grabowski[ca-compliance]2021-04-23T17:43:53Z
1706860Microsoft PKI Services: Certificate Mis-Issuance, DNSName is not FQDN, Preferred Name SyntaxASSIGNEDJohn Mason[ca-compliance]2021-04-22T20:08:40Z
1706950PKIoverheid: KPN issued Invalid organizationalUnitNameASSIGNEDJorik van 't Hof[ca-compliance]2021-04-23T13:14:26Z
1706967GTS: Forbidden Domain Validation Method 3.2.2.4.10ASSIGNEDAndy Warner[ca-compliance]2021-04-23T16:37:36Z
1706976GTS: Out-of-date CPS disclosureASSIGNEDAndy Warner[ca-compliance]2021-04-23T16:38:09Z
1707073GlobalSign: Invalid countryNameASSIGNEDEva Van Steenberge[ca-compliance]2021-04-23T21:08:29Z

36 Total;36 Open (100%);0 Resolved (0%);0 Verified (0%);


Audit Delays

Bugzilla

The compliance bug's whiteboard field is tagged with [audit-delay] whenever a CA is unable to deliver audit statements to Mozilla when they are due. Such bugs should be reported as CA compliance issues, with the following whiteboard tags as described here.

  • Whiteboard = [ca-compliance][audit-delay]
  • For audit delays due to mandated restrictions regarding COVID-19, use Whiteboard = [ca-compliance][audit-delay][covid-19]
Full Query
IDSummaryStatusAssigned toWhiteboardLast change time
1704140Camerfirma: Govern d'Andorra Audit DelayASSIGNEDAna Lopes[ca-compliance] [audit-delay] 2021-04-23T11:36:14Z

1 Total;1 Open (100%);0 Resolved (0%);0 Verified (0%);


Revocation Delays

The compliance bug's whiteboard field is tagged with [delayed-revocation-ca] or [delayed-revocation-leaf] whenever a CA fails to abide by Mozilla's requirement to revoke certificates in a timely fashion. As discussed in CA/Responding_To_An_Incident#Revocation, Mozilla recognizes that there may be *exceptional* situations that cause a CA to not abide by the Baseline Requirements, which should be accompanied by an Incident Report.

Such bugs should be reported as CA compliance issues, and will be categorized appropriately during triage.

Full Query
IDSummaryStatusAssigned toWhiteboardLast change time
1651447GlobalSign: Failure to revoke noncompliant ICA within 7 daysASSIGNEDArvid Vermote[ca-compliance] [delayed-revocation-ca]2021-01-12T13:19:27Z
1651637Firmaprofesional: Failure to revoke ICAs within 7 days: OCSP EKUASSIGNEDMaria Jose Prieto[ca-compliance] [delayed-revocation-ca] Next update 2021-04-232021-04-22T17:19:33Z
1692535Camerfirma: Delayed revocations of certificates issued by old CAs with an RSA modulus size of 2047 bitsASSIGNEDAna Lopes[ca-compliance][delayed-revocation-leaf]2021-04-19T14:49:20Z
1707229SECOM: Delayed Revocation of non-technically constrained FUJIFILM CertificatesASSIGNEDHisashi Kamo[ca-compliance] [delayed-revocation-leaf]2021-04-24T19:29:21Z

4 Total;4 Open (100%);0 Resolved (0%);0 Verified (0%);


Closed CA Compliance Bugs

Bugzilla Log In

A historical view of past CA compliance bugs may be found here:

Retrieved from 'https://wiki.mozilla.org/index.php?title=CA/Incident_Dashboard&oldid=1225532'

There are many ways to search Bugzilla, each with a substantial following.

QuickSearch

Mozilla bugzilla bmo

Bugzilla Mozilla Download

If you're already familiar with Bugzilla's fields, this is the fastest way to search. The search boxes in Bugzilla's header and footer are QuickSearch boxes. Assign it a keyword!

Advanced Search

Includes form elements for many of Bugzilla's fields, as well as 'boolean charts' that let you do complicated searches with any Bugzilla field. Includes some keyboard shortcuts, but still much more mouse-dependent than QuickSearch.

Find a specific bug

Awesomebar

Firefox Bug Tracker

Visited a bug recently, and want to get back to it? Just type a word from its summary into Firefox's address bar and let the awesomebar find it for you?





Comments are closed.