← DarkMatter LLC cases
Bugzilla #1521950
Certificate Problem Report
QuoVadis: BR Error - san dns name starts with period
RESOLVED
FIXED
DarkMatter LLC
AI Summary
QuoVadis identified a problem with eight certificates issued that contained Subject Alternative Names (SAN) starting with a period, which violates DNS naming conventions. The issue was discovered through post-issuance linting on January 22, 2019, and was promptly reported. The certificates were revoked on January 28, 2019, after a fix was deployed in the certificate management system. QuoVadis has since implemented pre-issuance linting to prevent similar issues in the future.
Chronology
- Issue discovered via post-issuance linting.
- Certificates were revoked.
- Pre-issuance linting implemented.
Participants
Stephen Davidson
Ryan Sleevi
Similar Local Cases
QuoVadis: EV serialNumber with "none"
QuoVadis: N/A in EV serialNumber field
QuoVadis: Incorrect keyUsage for ECC certificate
QuoVadis: use of Organisationidentifier field in EV (Pre CABF Ballot SC17)
QuoVadis: Failure to revoke certificates with compromised private keys
QuoVadis: Incorrect EV jurisdiction of incorporation information
QuoVadis: failure to reply to CPR in a timely manner
QuoVadis: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy or the BRs