← e-tugra cases
Bugzilla #1462797 Certificate Misissuance

E-Tugra: Improper DER results in failure to comply with RFC 5280 (invalid PrintableString characters)

RESOLVED FIXED e-tugra
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The case concerns an E-Tugra certificate that fails to parse due to invalid characters in a Subject serialNumber field: the serialNumber contains an underscore (“_”), which is not valid for a PrintableString, and the certificate also includes a Subject attribute with a serialNumber field. Ryan Sleevi (Mozilla) provided an example certificate URL and stated it appears to be a misissued certificate and asked E-Tugra to provide an incident report. E-Tugra responded that it continued reviewing the case and later provided an incident report describing how it became aware of the problem and what actions it took. E-Tugra stated it revoked the affected certificates (including those reported in Bugzilla) and issued a replacement certificate for the certificate owner, with revocation planned “in a week” in the earlier response. E-Tugra also reported that it searched its certificate database and found no other certificates with the same problem, upgraded its pre-issue and post-issue control libraries, and rebuilt certificate issue controls based on RFC 5280 and CA/Browser Forum Baseline Requirements, with controls put into use on Jan 31. Fastly’s wthayer later commented that it appears remediation is complete, and the bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 17:49 UTC Revised: 2026-06-16 18:30 UTC Confidence: 0.86 10 comments
Chronology
  1. A misissued E-Tugra certificate example was identified as failing to parse due to invalid PrintableString characters in a Subject serialNumber field.
  2. E-Tugra revoked the certificates it identified as affected, including those reported in the Bugzilla case.
  3. E-Tugra reported that system upgrades rebuilt certificate issue controls and that reasons for the problems were fixed with auto control and alerting introduced.
  4. A reviewer stated it appears remediation is complete.
Thread Activity
  1. Community commenter — Provided an example certificate URL and explained it fails to parse because the Subject serialNumber contains an underscore, which is not valid for PrintableString.
  2. Fastly representative — Agreed it appears to be a misissued certificate and requested an incident report posted to the mozilla.dev.security.policy forum and added to the bug.
  3. E-Tugra — Said E-Tugra would provide an incident report as soon as possible.
  4. E-Tugra — Explained that invalid certificates were issued during testing of a new intermediate CA, described three levels of certificate controls, and said a detailed report would be posted.
  5. E-Tugra — Provided an incident-report style response including awareness sources, a timeline of issuance and revocation, and stated controls were rebuilt with pre-issue and post-issue changes.
  6. Fastly representative — Thanked E-Tugra for the detailed response and said it appears remediation is complete.
Participants
Community commenter Fastly representative E-Tugra
Similar Local Cases
#1449371 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2018-03-27 · Closed 2023-02-22 · 82% similar
E-Tugra: Validity period > 825 days
#1527423 RESOLVED Certificate Misissuance Opened 2019-02-12 · Closed 2023-02-22 · 80% similar
DigiCert: P-384,ecdsa-with-SHA512 Certificates
#1586792 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-10-07 · Closed 2023-02-22 · 79% similar
QuoVadis: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy or the BRs
#1463975 RESOLVED Certificate Misissuance Delayed Revocation Opened 2018-05-24 · Closed 2023-02-22 · 78% similar
GRCA: Misissued certificates: Invalid commonName, commonName not in SAN
#1390990 RESOLVED Certificate Misissuance Delayed Revocation Opened 2017-08-16 · Closed 2023-02-22 · 78% similar
D-TRUST: Non-BR-Compliant Certificate Issuance
#1524730 RESOLVED Certificate Misissuance Revocation Issue Opened 2019-02-02 · Closed 2023-02-22 · 77% similar
Sectigo: invalid dnsName
#1524876 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-02-03 · Closed 2023-02-22 · 77% similar
Entrust: IP in dnsName
#1536287 RESOLVED Certificate Misissuance Opened 2019-03-18 · Closed 2023-02-22 · 77% similar
Entrust: AffirmTrust Issuing CA Impacted by EJBCA Serial Number Issue

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action