← DarkMatter LLC cases
Bugzilla #1493760
Certificate Misissuance
QuoVadis: improper countryName format
RESOLVED
FIXED
DarkMatter LLC
AI Summary
QuoVadis issued four certificates with an incorrect countryName format, using 'Germany' instead of the required ISO code 'DE'. This issue arose during a transition to a managed PKI system, where a manual import of organization details led to the incorrect formatting not being caught by existing filters. The certificates were identified and revoked shortly after issuance, and improvements to the Managed PKI interface and processes have been implemented to prevent future occurrences.
Chronology
- QuoVadis issued certificates with incorrect countryName format.
- Certificates identified and revocation process initiated.
- Confirmation of certificate revocation.
Participants
Stephen Davidson
W. Thayer
External References
Similar Local Cases
QuoVadis: Non-BR-Compliant issuance --improper characters in DNSName (BIT sub-CA)
QuoVadis: IPaddress in DNSname SAN
QuoVadis: Multiple unreported misissuances in 2018
QuoVadis: Certificate containing Debian weak key
QuoVadis: Non-BR-Compliant OCSP Responder
Entrust: Certificate Issued with Incorrect Country Code
SwissSign: Domain validated certificate but with stateOrProvinceName
Entrust: Late mis-issue certificate revocation