← Krajowa Izba Rozliczeniowa S.A. (KIR) cases
Bugzilla #1495497 Certificate Misissuance

KIR S.A.: Certificates issued with multiple BR violations

RESOLVED FIXED Krajowa Izba Rozliczeniowa S.A. (KIR)
AI Summary

Krajowa Izba Rozliczeniowa S.A. (KIR) faced multiple violations of the Baseline Requirements (BR) for certificates issued from the SZAFIR ROOT CA2. Issues included invalid postal addresses, incorrect Subject Alternative Names (SANs), and missing state or locality fields in organization names. An incident report was prepared and shared, detailing the timeline of actions taken to address the violations, including contacting certificate owners and issuing new compliant certificates. The CA has since implemented measures to prevent future misissuance, including post-issuance linting and a review of certificate policy templates.

Model: gpt-4o-mini Generated: 2026-06-13 17:54 UTC Confidence: 0.95
Chronology
  1. Initial report of BR violations by CABLint, X509Lint, and ZLint.
  2. KIR began preparing an incident report.
  3. KIR disclosed the incident report detailing the violations and remediation steps.
  4. Post-issuance linting procedure officially implemented.
  5. Configuration issue identified and resolved.
  6. All questions answered and remediation deemed complete.
Participants
Wayne Thayer Piotr Grabowski
Similar Local Cases
#1523186 RESOLVED Certificate Misissuance Opened 2019-01-27 · Closed 2023-02-22 · 69% similar
KIR S.A.: Misissuance - missing OCSP AIA, Validity > 825 days
#1446121 RESOLVED Certificate Misissuance Opened 2018-03-15 · Closed 2023-02-22 · 52% similar
IdenTrust: Improper encoding of wildcard certificate
#1500593 RESOLVED Certificate Misissuance Opened 2018-10-19 · Closed 2023-02-22 · 50% similar
IdenTrust: Internal names / failure to report
#1472052 RESOLVED Certificate Misissuance Opened 2018-06-29 · Closed 2023-02-22 · 50% similar
QuoVadis: Certificate containing Debian weak key
#1551363 RESOLVED Certificate Misissuance Opened 2019-05-14 · Closed 2023-02-22 · 50% similar
DigiCert: "Some-State" in stateOrProvinceName
#1463975 RESOLVED Certificate Misissuance Opened 2018-05-24 · Closed 2023-02-22 · 50% similar
GRCA: Misissued certificates: Invalid commonName, commonName not in SAN
#1462844 RESOLVED Certificate Misissuance Opened 2018-05-19 · Closed 2023-02-22 · 50% similar
GoDaddy: Improper DER results in failure to comply with RFC 5280 - Invalid characters in PrintableString
#1455147 RESOLVED Certificate Misissuance Opened 2018-04-18 · Closed 2023-02-22 · 50% similar
Camerfirma: Missing audit for Intermediate certificate

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action