← SwissSign AG cases
Bugzilla #1506607
Certificate Misissuance
SwissSign: Misissuance of Intermediate Certificates because of incorrect organizationIdentifier
RESOLVED
FIXED
SwissSign AG
AI Summary
SwissSign AG reported a misissuance of six intermediate certificates due to an incorrect organizationIdentifier. The error was discovered during an internal review on November 9, 2018, leading to an immediate internal incident management process. The organizationIdentifier was incorrectly documented as 'FL-0002.523.017-8' instead of the correct 'NTRLI-FL-0002.523.017-8'. No leaf certificates were affected, as the intermediate certificates had not yet been used for production. SwissSign has since implemented corrective measures and technical safeguards to prevent future occurrences.
Chronology
- Issue detected during internal review
- Root cause analysis initiated
- Technical safeguard successfully deployed
Participants
Mike Guenther
W. Thayer
Ryan Sleevi
External References
Similar Local Cases
SwissSign: Misissuance of Leaf Certificates because of incorrect postcode
SwissSign: Misissuance with mispellings in Location for a number of Certificates
SwissSign: Invalid DNSName in SAN
SwissSign: Mis-Issuance of S/MIME certificates
SwissSign: Domain validated certificate but with stateOrProvinceName
SwissSign: Certificate with key length 16258
SwissSign: wrong address in EV certificate
SwissSign: Certificate with key length 4098 bit