← SwissSign AG cases
Bugzilla #1459557 Self Reported Incident Certificate Misissuance

SwissSign: Certificate issue with Signature (incident report)

RESOLVED FIXED SwissSign AG
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

SwissSign reported an incident in which it issued certificates with signature issues. The post-issue compliance system alerted SwissSign on 2018-05-07 02:01 UTC to a problem reported by cablint: “ERROR: RSA signatures must have a parameter specified.” SwissSign stated that it stopped issuing certificates after becoming aware of the problem and released a fix, after which it started issuing certificates again. SwissSign also said it informed customers about the incident and exchanged affected certificates. The report included that 19 certificates were affected, with first issuance on 2018-05-05 09:25:45 GMT and last issuance on 2018-05-07 06:55:57 GMT. SwissSign later stated that all affected certificates were revoked as of 2018-05-09 12:00 UTC, and described adding internal pre-issuance linting to prevent recurrence. The bug was resolved, and SwissSign later noted that pre-issuance linting for newly produced certificates was established and activated in September 2018, and that there had been a lack of notification to Bugzilla due to personnel changes.

Model: gpt-5.4-nano Generated: 2026-06-13 17:48 UTC Revised: 2026-06-16 18:15 UTC Confidence: 0.86 6 comments
Chronology
  1. SwissSign issued the first certificates later identified as having RSA signature parameter issues.
  2. SwissSign’s post-issue compliance system alerted it to the signature-parameter problem and it stopped issuing certificates.
  3. SwissSign stated that all affected certificates were revoked.
  4. SwissSign established and activated pre-issuance linting for newly produced certificates.
Thread Activity
  1. SwissSign AG — SwissSign initiated an incident report, stating that its post-issue compliance system alerted it on 2018-05-07 02:01 UTC to a cablint-reported RSA signature parameter error and that it would provide the incident report in this bug.
  2. SwissSign AG — SwissSign provided a timeline including stopping issuance, releasing a fix, restarting issuance, and informing customers/exchanging affected certificates; it also described the problematic certificates and stated that release 4.11 introduced a change in ASN1 generation that caused the missing RSA signature parameter.
  3. Fastly representative — Fastly thanked SwissSign and asked that the bug be updated when its staging environment compliance system was live.
  4. SwissSign AG — SwissSign stated that all affected certificates were now revoked as of 2018-05-09 12:00 UTC.
  5. SwissSign AG — SwissSign said it would have an internal pre-issue linting system in place by end of June and planned to use it for public trusted SSL certificates by end of July.
  6. SwissSign AG — Juerg Eiholzer stated that pre-issuance linting was established and activated in September 2018, and that the item could be resolved; he also noted a lack of notification to Bugzilla due to personnel changes.
Participants
SwissSign AG Fastly representative
Similar Local Cases
#1825232 RESOLVED Certificate Misissuance Self Reported Incident Opened 2023-03-29 · Closed 2023-03-31 · 91% similar
SwissSign: Invalid CT data in issued certs (SABRE.CT misconfiguration)
#1541064 RESOLVED Certificate Misissuance Opened 2019-04-02 · Closed 2023-02-22 · 90% similar
SwissSign: Error in OrganisationIdentifier in signature/seal certificate
#1443731 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2018-03-07 · Closed 2023-02-22 · 87% similar
SwissSign: Cert issued with a to long validity period
#1473971 RESOLVED Self Reported Incident Certificate Misissuance Opened 2018-07-06 · Closed 2023-02-22 · 87% similar
SwissSign: Domain validated certificate but with stateOrProvinceName
#1670894 RESOLVED Certificate Misissuance Opened 2020-10-13 · Closed 2023-02-22 · 83% similar
SwissSign: Invalid stateOrProvinceName field
#1851164 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-09-01 · Closed 2023-09-22 · 83% similar
SwissSign: S/MIME wrong key Usage
#1691704 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-02-09 · Closed 2023-02-22 · 82% similar
SwissSign: Certificate with key length 4098 bit
#1734131 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-10-05 · Closed 2023-02-22 · 82% similar
SwissSign: wrong address in EV certificate

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action