← SwissSign AG cases
Bugzilla #1473971
Certificate Misissuance
SwissSign: Domain validated certificate but with stateOrProvinceName
RESOLVED
FIXED
SwissSign AG
AI Summary
SwissSign AG identified an issue where they issued domain validated certificates that incorrectly included the 'stateOrProvinceName' field. This was discovered during routine checks on crt.sh, leading to immediate corrective actions. The CA ceased issuing such certificates and informed affected customers for revocation. A total of 10 certificates were impacted, with the first issued on May 28, 2018, and the last on July 3, 2018. The issue was resolved, and measures are being implemented to prevent future occurrences.
Chronology
- Issue discovered during routine checks
- Stopped issuing problematic certificates
- Informed customers and requested revocation
- All affected certificates revoked
Participants
Reinhard Dietrich
W. Thayer
External References
Similar Local Cases
SwissSign: Misissuance of Intermediate Certificates because of incorrect organizationIdentifier
SwissSign: Two certs issued with same issuer and serial number
SwissSign: Invalid DNSName in SAN
SwissSign: Cert issued with a to long validity period
SwissSign: Misissuance of Leaf Certificates because of incorrect postcode
SwissSign: Mis-Issuance of S/MIME certificates
SwissSign: S/MIME LCP: CN with values other than email address
SwissSign: Cert issued with a to long validity period