← Krajowa Izba Rozliczeniowa S.A. (KIR) cases
Bugzilla #1523186
Certificate Misissuance
KIR S.A.: Misissuance - missing OCSP AIA, Validity > 825 days
RESOLVED
FIXED
Krajowa Izba Rozliczeniowa S.A. (KIR)
AI Summary
Krajowa Izba Rozliczeniowa S.A. (KIR) reported a misissuance incident involving a certificate that lacked an OCSP AIA and had a validity period exceeding 825 days. The issue was identified during a post-issuance linting procedure, leading to a series of corrective actions including the revocation of the problematic certificate and the implementation of a patch to prevent future occurrences. KIR has since updated its policies and procedures to enhance compliance and prevent similar issues.
Chronology
- Certificate without OCSP AIA issued.
- Root cause investigation initiated.
- Problematic certificate revoked.
- Basic pre-linting patch deployed.
Participants
Piotr Grabowski
Wayne Thayer
Ryan Sleevi
External References
Similar Local Cases
KIR S.A.: Certificates issued with multiple BR violations
Microsoft PKI Services: Certificate Mis-Issuance, Locality Missing
Telia: "Some-State" in stateOrProvinceName
QuoVadis: Multiple unreported misissuances in 2018
SECOM: Mis-issued EV Certificates
Camerfirma: Infocert misissued certificates
DigiCert: Domain validation skipped
Asseco DS / Certum: Invalid value in SAN dNSName