← Telia Company cases
Bugzilla #1528259
Certificate Misissuance
Telia: misissued certificate - FQDN value incorrectly in SAN rfc822 field
RESOLVED
FIXED
Telia Company
AI Summary
Telia Company identified a misissued certificate during a mass lint scan of its SSL certificates. The scan, conducted on February 8, 2019, revealed nine invalid certificates across various error categories, including one with an FQDN value incorrectly placed in the SAN rfc822 field. The certificate was created in 2016 and was promptly revoked within the required timeframe. Telia has since implemented measures to prevent similar issues, including ceasing the use of the problematic certificate creation console and enhancing their certificate issuance processes.
Chronology
- Discovery of invalid certificates during mass lint scan
- Preliminary analysis and decision to revoke the misissued certificate
- Certificate revoked by Telia CA
- Quick analysis confirming similar errors cannot occur in current systems
- Root cause analysis conducted
Participants
pekka.lahtiharju@teliasonera.com
External References
Similar Local Cases
Telia: Misissued certificate - Invalid wildcard format
Telia: Misissued certificate - Invalid OU value "-"
Telia: Misissued certificate - FQDN without domain part (e_dnsname_not_valid_tld)
Telia: invalid IP value in SAN DNS field
Telia: Misissued certificate - wrong OrganizationName value "Hair 8 Brains"
Telia: Ambiguity on KeyUsage with ECC public key
Telia: Non-BR-Compliant OCSP Responder
Telia: TLS certificates issued in violation of TLS BR v2.0.1