← Swisscom (Switzerland) Ltd cases
Bugzilla #1195115 Certificate Misissuance

Swisscom: certificates without DNS names in subjectAltName

RESOLVED WONTFIX Swisscom (Switzerland) Ltd
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The bug reports that Swisscom, an EV-qualified CA trusted by Mozilla, issued SSL certificates whose subjectAltName contained only an email entry and no DNS name, meaning clients would have to rely on the certificate Common Name for validation. The reporter provided examples of certificates and noted that the issue conflicted with CAB Forum Baseline Requirements for subjectAltName contents. Mozilla asked Swisscom to explain why such certificates were issued and referenced an earlier CA communication about interoperability workarounds and planned removal of those workarounds. Swisscom acknowledged that it was still issuing non-EV SSL server certificates without a valid subject alternative name and stated it would take technical and administrative actions to ensure future certificates include a valid subjectAltName with a DNS name or IP. The thread also discusses the timing of when CN fallback would be removed, including a Mozilla clarification that CN fallback was disabled for certificates with notBefore dates later than 23 August 2016, shipping in Firefox 48. Later, Swisscom stated it stopped issuing SSL certificates and suggested closing the issue because the trust bit would be removed and acceptance of existing certificates would be terminated. The bug was resolved with resolution set to WONTFIX.

Model: gpt-5.4-nano Generated: 2026-06-13 14:01 UTC Revised: 2026-06-16 18:36 UTC Confidence: 0.84 10 comments
Chronology
  1. A report was filed alleging Swisscom-issued SSL certificates lacked DNS names in subjectAltName.
  2. Swisscom acknowledged continuing issuance of certificates without a valid subjectAltName and committed to corrective actions for future issuance.
  3. Mozilla clarified that CN fallback was disabled for certificates with notBefore dates later than 23 August 2016, affecting validation in Firefox 48.
  4. Swisscom stated it stopped issuing SSL certificates and that the trust bit would be removed, suggesting closure of the issue.
Thread Activity
  1. Community commenter — Reported that Swisscom issued SSL certificates with only email in subjectAltName and no DNS name, and provided crt.sh links and certificate details.
  2. Mozilla representative — Asked for an explanation from Swisscom about why certificates were issued without DNS names in subjectAltName, citing CAB-Forum-BR-1.3.0 section 7.1.4.2.1.
  3. Mozilla representative — Corrected the addressee and reiterated the request for an explanation referencing the CAB Forum requirement.
  4. Mozilla representative — Noted that the issue was tracked as a BR-Compliance issue and referenced Mozilla’s CA communication and interoperability workarounds, including a link to the mozpkix testing page.
  5. Swisscom representative — Acknowledged Swisscom still issued non-EV SSL server certificates without a valid subjectAltName and described immediate steps to ensure future certificates include a valid subjectAltName with DNS name or IP.
  6. Community commenter — Responded that CN fallback had already been disabled on devices and linked to related bugs about removing CN fallback.
  7. Swisscom representative — Asked for timing details on when the mechanism of fallback removal would be active and what else Swisscom should do to have the issue marked resolved.
  8. Mozilla representative — Clarified that the relevant CN fallback removal was implemented for certificates with notBefore dates later than 23 August 2016, shipped in Firefox 48, and that newly issued certificates without appropriate subjectAltName entries would not validate.
  9. Swisscom representative — Stated Swisscom stopped issuing SSL certificates, that the websites trust bit would be removed (linking to another bug), and suggested closing the issue.
  10. Swisscom representative — Noted a corrected wrong reason.
Participants
Community commenter Mozilla representative Swisscom representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1315018 RESOLVED Certificate Misissuance Opened 2016-11-03 · Closed 2022-11-14 · 69% similar
SHA-1 issuance by GlobalSign root
#1398428 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-09-09 · Closed 2023-02-22 · 69% similar
Amazon Trust Services: CAA Misissuances
#682956 RESOLVED Certificate Misissuance Opened 2011-08-29 · Closed 2022-11-14 · 66% similar
Investigate *.google.com certificate issued by DigiNotar and used by Iran government?
#1398269 RESOLVED Certificate Misissuance Opened 2017-09-08 · Closed 2023-02-22 · 66% similar
DigiCert: Non-BR-Compliant OCSP Responders
#1579299 RESOLVED Repository Issue Certificate Misissuance Opened 2019-09-06 · Closed 2023-02-22 · 66% similar
Asseco DS / Certum: non-audited intermediate certificate
#2041774 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Repository Issue Opened 2026-05-22 Still Open · 60% similar
OATI: AIA CA Issuer field pointing to PEM encoded cert
#1942130 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2025-01-16 · Closed 2025-05-01 · 60% similar
HARICA: S/MIME certificate issuance without proper validation
#1625421 RESOLVED Certificate Misissuance Opened 2020-03-27 · Closed 2024-05-09 · 60% similar
FNMT: QC Statement that contains at least one of the ETSI ESI statements

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action