SwissSign: Cert issued with a to long validity period
SwissSign notified Mozilla that it had issued an SSL certificate with a validity period that was too long. The notification was made by SwissSign’s Reinhard Dietrich, who referenced a certificate entry on crt.sh and stated that an incident report would be provided according to Mozilla’s misissuance incident report guidance. In the thread, Alex Gaynor indicated that the issue appeared to be an accidental copy of bug 1443731 and noted that this bug had been marked as a duplicate of bug 1443731. The bug’s resolution is listed as DUPLICATE, and the current status is RESOLVED. No additional remediation details beyond the intent to provide an incident report are stated in the provided comments.
- SwissSign issued an SSL certificate with a validity period longer than allowed and disclosed the incident to Mozilla.
- SwissSign AG — Reinhard Dietrich informed Mozilla that SwissSign issued an SSL certificate with a too-long validity period and said an incident report would be provided per Mozilla’s misissuance incident report guidance.
- Community commenter — Alex Gaynor said the bug looked like an accidental copy of bug 1443731 and that this bug was marked as a duplicate of bug 1443731.