Swisscom: certificates without DNS names in subjectAltName
The bug reports that Swisscom, an EV-qualified CA trusted by Mozilla, issued SSL certificates whose subjectAltName contained only an email entry and no DNS name, meaning clients would have to rely on the certificate Common Name for validation. The reporter provided examples of certificates and noted that the issue conflicted with CAB Forum Baseline Requirements for subjectAltName contents. Mozilla asked Swisscom to explain why such certificates were issued and referenced an earlier CA communication about interoperability workarounds and planned removal of those workarounds. Swisscom acknowledged that it was still issuing non-EV SSL server certificates without a valid subject alternative name and stated it would take technical and administrative actions to ensure future certificates include a valid subjectAltName with a DNS name or IP. The thread also discusses the timing of when CN fallback would be removed, including a Mozilla clarification that CN fallback was disabled for certificates with notBefore dates later than 23 August 2016, shipping in Firefox 48. Later, Swisscom stated it stopped issuing SSL certificates and suggested closing the issue because the trust bit would be removed and acceptance of existing certificates would be terminated. The bug was resolved with resolution set to WONTFIX.
- A report was filed alleging Swisscom-issued SSL certificates lacked DNS names in subjectAltName.
- Swisscom acknowledged continuing issuance of certificates without a valid subjectAltName and committed to corrective actions for future issuance.
- Mozilla clarified that CN fallback was disabled for certificates with notBefore dates later than 23 August 2016, affecting validation in Firefox 48.
- Swisscom stated it stopped issuing SSL certificates and that the trust bit would be removed, suggesting closure of the issue.
- Community commenter — Reported that Swisscom issued SSL certificates with only email in subjectAltName and no DNS name, and provided crt.sh links and certificate details.
- Mozilla representative — Asked for an explanation from Swisscom about why certificates were issued without DNS names in subjectAltName, citing CAB-Forum-BR-1.3.0 section 7.1.4.2.1.
- Mozilla representative — Corrected the addressee and reiterated the request for an explanation referencing the CAB Forum requirement.
- Mozilla representative — Noted that the issue was tracked as a BR-Compliance issue and referenced Mozilla’s CA communication and interoperability workarounds, including a link to the mozpkix testing page.
- Swisscom representative — Acknowledged Swisscom still issued non-EV SSL server certificates without a valid subjectAltName and described immediate steps to ensure future certificates include a valid subjectAltName with DNS name or IP.
- Community commenter — Responded that CN fallback had already been disabled on devices and linked to related bugs about removing CN fallback.
- Swisscom representative — Asked for timing details on when the mechanism of fallback removal would be active and what else Swisscom should do to have the issue marked resolved.
- Mozilla representative — Clarified that the relevant CN fallback removal was implemented for certificates with notBefore dates later than 23 August 2016, shipped in Firefox 48, and that newly issued certificates without appropriate subjectAltName entries would not validate.
- Swisscom representative — Stated Swisscom stopped issuing SSL certificates, that the websites trust bit would be removed (linking to another bug), and suggested closing the issue.
- Swisscom representative — Noted a corrected wrong reason.