← MULTICERT cases
Bugzilla #1502957 Certificate Misissuance

Camerfirma: MULTICERT Misissuance and missing audits

RESOLVED FIXED MULTICERT
AI Summary

The case involves MULTICERT's misissuance of 174 certificates due to invalid QCStatements, which violated the syntax of the qcStatements extension. Additionally, it was discovered that the MULTICERT SSL Certification Authority 001 was not included in the scope of the required audits, leading to compliance issues. The audit for MULTICERT did not cover all necessary periods, resulting in a gap that was only addressed through a memo from the auditor. Despite efforts to remediate the situation, including stopping certificate issuance and reissuing affected certificates, concerns about compliance remain unresolved.

Model: gpt-4o-mini Generated: 2026-06-13 17:56 UTC Confidence: 0.90
Chronology
  1. Misissuance reported by Ryan Sleevi.
  2. MULTICERT provides audit attestation letter.
  3. Incident report detailing actions taken by MULTICERT.
  4. Discussion on audit gaps and compliance.
  5. New audit reports submitted.
  6. Concerns raised about audit compliance.
  7. Summary of unresolved compliance issues.
Participants
Wayne Thayer Juan Angel Martin Ryan Sleevi Eusebio Herrera Kathleen Wilson
External References
Similar Local Cases
#1481862 RESOLVED Certificate Misissuance Opened 2018-08-08 · Closed 2023-02-22 · 74% similar
Camerfirma: MULTICERT organizationName Too Long
#1502957 RESOLVED Certificate Misissuance Opened 2018-10-29 · Closed 2023-02-22 · 74% similar
Camerfirma: MULTICERT Misissuance and missing audits
#1556806 RESOLVED Certificate Misissuance Opened 2019-06-04 · Closed 2023-02-22 · 63% similar
Camerfirma: Infocert misissued certificates
#1524871 RESOLVED Certificate Misissuance Opened 2019-02-03 · Closed 2023-02-22 · 61% similar
Camerfirma: failure to revoke underscores
#1557085 RESOLVED Certificate Misissuance Opened 2019-06-05 · Closed 2023-02-22 · 56% similar
Camerfirma: Intesa Sanpaolo misissued certificates
#1428877 RESOLVED Certificate Misissuance Opened 2018-01-08 · Closed 2023-02-22 · 56% similar
SwissSign: Invalid DNSName in SAN
#1462844 RESOLVED Certificate Misissuance Opened 2018-05-19 · Closed 2023-02-22 · 56% similar
GoDaddy: Improper DER results in failure to comply with RFC 5280 - Invalid characters in PrintableString
#1717357 RESOLVED Certificate Misissuance Opened 2021-06-20 · Closed 2023-02-22 · 55% similar
Actalis: Issuance of intermediates after 2020-08-20 that do not comply with Mozilla Policy and the Baseline Requirements

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action