← SwissSign AG cases
Bugzilla #1455132
Certificate Misissuance
SwissSign: Undisclosed Intermediate Certificates
RESOLVED
FIXED
SwissSign AG
AI Summary
SwissSign AG failed to disclose several intermediate CA certificates in the CCADB, violating Mozilla's root store policy. The issue was raised in April 2018, prompting SwissSign to analyze the situation and eventually disclose the certificates by October 2018. An incident report detailing the oversight and corrective measures was requested to ensure compliance moving forward. The case was resolved after the certificates were disclosed and the incident report was submitted.
Chronology
- Initial report of undisclosed intermediate CA certificates.
- SwissSign disclosed the undisclosed certificates.
- SwissSign submitted the incident report.
Participants
Wayne Thayer
Juerg Eiholzer
Cornelia Enke
External References
Similar Local Cases
SwissSign: Cert issued with a to long validity period
SwissSign: Cert issued with a to long validity period
SwissSign: Invalid DNSName in SAN
SECOM: Undisclosed intermediate certificates
Camerfirma: Missing audit for Intermediate certificate
DocuSign/Keynectis: Undisclosed Intermediate certificate
Firmaprofesional: Undisclosed Intermediate certificate
SwissSign: modified fields were not saved into certificates and resulted in miss-issuance