← MULTICERT cases
Bugzilla #1481862
Certificate Misissuance
Camerfirma: MULTICERT organizationName Too Long
RESOLVED
FIXED
MULTICERT
AI Summary
The case involves MULTICERT issuing certificates with an invalid organizationName that exceeded the allowed length, violating ASN.1 size constraints. The issue was detected on August 3, 2018, leading to the revocation of five misissued certificates. MULTICERT implemented operational controls to prevent future occurrences, including monitoring for misissued certificates and deploying a linting tool. However, there were initial delays in deploying these controls, which raised concerns about the effectiveness of their oversight processes. All remediation actions have since been completed.
Chronology
- MULTICERT detected misissued certificates and initiated revocation.
- Technical controls were deployed to limit organizationName length.
- Camerfirma deployed a post-issuance linting tool.
- Pre-issuance linting was implemented.
Participants
Wayne Thayer
Juan Angel Martin
Ryan Sleevi
External References
Similar Local Cases
Camerfirma: MULTICERT Misissuance and missing audits
Camerfirma: MULTICERT organizationName Too Long
Camerfirma: MULTICERT Misissuance and missing audits
Telia: "Some-State" in stateOrProvinceName
Hongkong Post / Certizen: Failure to report misissuance
Camerfirma: Infocert misissued certificates
Kamu SM: "Some-State" in stateOrProvinceName
Camerfirma: failure to revoke underscores