← SwissSign AG cases
Bugzilla #1391066
Ca Certificate Compliance
SwissSign: Non-BR-Compliant Certificate Issuance
RESOLVED
FIXED
SwissSign AG
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
SwissSign AG disclosed a compliance failure regarding the issuance of non-Baseline Requirements (BR) compliant certificates. The CA became aware of the issues through reports in the mozilla.dev.security.policy forum and took immediate action by revoking the problematic certificates and implementing technical measures to prevent future occurrences. The CA provided a detailed remediation plan, including a timeline for addressing the identified issues. As of November 30, 2017, all relevant certificates have been revoked, and the CA has confirmed that the issues have been resolved.
Chronology
- SwissSign became aware of compliance issues and initiated corrective actions.
- All relevant certificates were revoked.
Thread Activity
- Mozilla representative — Reported compliance issues found in certificates issued by SwissSign.
- SwissSign AG — Confirmed revocation of non-conformant certificates and implementation of technical measures.
- SwissSign AG — Announced release of software addressing outstanding issues.
- SwissSign AG — Final confirmation that all relevant certificates have been revoked.
Participants
Mozilla representative
SwissSign AG
Community commenter
Titanous representative
External References
Similar Local Cases
DocuSign/Keynectis: Non-BR-Compliant Certificate Issuance
NetLock: Non-BR-Compliant Certificate Issuance
Microsec: Non-BR-Compliant Certificate Issuance
GlobalSign: Non-BR-Compliant Certificate Issuance - metadata-only subject fields
Disig: Non-BR-Compliant Certificate Issuance
SwissSign: Cert issued with a to long validity period
DocuSign/Keynectis: Non-BR-Compliant OCSP Responders
Firmaprofesional: Non-audited, non-technically-constrained intermediate certificates