← SwissSign AG cases
Bugzilla #1443731 Ca Certificate Compliance Certificate Misissuance

SwissSign: Certificate issued with too long validity period (reissue option misuse)

RESOLVED FIXED SwissSign AG
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

SwissSign reported that it had issued an SSL certificate with a too-long validity period. The CA said it became aware of the problem when its CABLint post-issue test system alerted it on the evening of 6 March 2018, and it also received emails from an external source. SwissSign stated it started an investigation, contacted the customer to replace the certificate and revoke the mis-issued one, and then revoked the certificate on 7 March 2018. The CA identified the source as incorrect use of a rarely used reissue option available only to SwissSign support employees, and said it immediately prohibited any use of this functionality until it was fixed (ETA 17 March 2018). In its incident report content, SwissSign described that the support option was not in scope during initial implementation work and that support staff were trained to use the functionality with caution in the interim. SwissSign later reported that it would begin pre-issuance linting for all public trusted SSL certificates in early July and provided an update that pre-issuance linting was activated in September 2018; the bug was resolved as FIXED. The thread also includes requests to email the incident report to the mozilla.dev.security.policy forum and follow-up questions about why the code path was not patched earlier.

Model: gpt-5.4-nano Generated: 2026-06-13 17:44 UTC Revised: 2026-06-16 18:14 UTC Confidence: 0.90 9 comments
Chronology
  1. CABLint post-issue test system alerted SwissSign to the too-long validity issue.
  2. SwissSign issued the mis-issued SSL certificate and subsequently revoked it after investigating and contacting the customer.
  3. SwissSign planned rollout of fixes to constrain the reissue functionality to 825 days for SSL certificates.
  4. SwissSign activated pre-issuance linting for newly produced certificates.
Thread Activity
  1. SwissSign AG — SwissSign informed Mozilla it had issued an SSL certificate with a too-long validity period and said it would provide an incident report per Mozilla’s misissuance incident report guidance.
  2. Community commenter — A duplicate marker was set indicating Bug 1443733 was marked as a duplicate of this bug.
  3. SwissSign AG — SwissSign posted the incident report details, including how it discovered the issue, its response steps, the identified cause (misuse of a rarely used reissue option), and immediate/expected remediation actions including prohibiting the functionality and constraining reissue to 825 days.
  4. Fastly representative — Fastly requested that the incident report be emailed to the mozilla.dev.security.policy forum and asked follow-up questions about why the code path wasn’t patched and when pre-issuance linting would begin.
  5. SwissSign AG — SwissSign stated it would email the incident report to the mozilla.dev.security.policy forum and noted it had also posted it on the forum.
  6. Fastly representative — Fastly thanked SwissSign and asked again for answers to the questions from the earlier comment.
  7. SwissSign AG — SwissSign answered why the code path wasn’t patched earlier and stated it would have a pre-issuance linting system in place by end of June and start using it in early July.
  8. SwissSign AG — SwissSign reported it was in quality assurance for the pre-issuance linting system and planned to place it into operation product by product in the coming months.
  9. SwissSign AG — SwissSign stated pre-issuance linting for newly produced certificates was established and activated in September 2018 and that the item could be resolved, noting a lack of notification to Bugzilla.
Participants
SwissSign AG Community commenter Fastly representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1473971 RESOLVED Self Reported Incident Certificate Misissuance Opened 2018-07-06 · Closed 2023-02-22 · 96% similar
SwissSign: Domain validated certificate but with stateOrProvinceName
#1731586 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Opened 2021-09-20 · Closed 2023-02-22 · 90% similar
SwissSign: Certificate with key length 16258
#1428877 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2018-01-08 · Closed 2023-02-22 · 89% similar
SwissSign: Invalid DNSName in SAN
#1551364 RESOLVED Certificate Misissuance Opened 2019-05-14 · Closed 2023-02-22 · 89% similar
SwissSign: "Some-State" in stateOrProvinceName
#1391066 RESOLVED Ca Certificate Compliance Opened 2017-08-16 · Closed 2023-02-22 · 88% similar
SwissSign: Non-BR-Compliant Certificate Issuance
#1569651 RESOLVED Certificate Misissuance Opened 2019-07-29 · Closed 2023-02-22 · 88% similar
SwissSign: Misissuance of Leaf Certificates because of incorrect postcode
#1459557 RESOLVED Self Reported Incident Certificate Misissuance Opened 2018-05-07 · Closed 2023-02-22 · 87% similar
SwissSign: Certificate issue with Signature
#1506607 RESOLVED Self Reported Incident Certificate Misissuance Opened 2018-11-12 · Closed 2026-06-10 · 87% similar
SwissSign: Misissuance of Intermediate Certificates because of incorrect organizationIdentifier

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action