← Telia Company cases
Bugzilla #1528264 Certificate Misissuance

Telia: Misissued certificate - Invalid OU value "-"

RESOLVED FIXED Telia Company
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Telia reported that it discovered nine invalid certificates during a mass lint scan of its SSL certificates on February 8, 2019. The certificates were found in multiple error categories, including three certificates with an invalid OU value "-" (e_subject_contains_noninformational_value). Telia said it performed preliminary analysis and determined the certificates should be revoked within 24 hours and must be revoked within 5 days, and it revoked the affected certificates on February 8, 2019. Telia later stated that it fixed the underlying OU verification code bug in Summer 2018 and that the issue could not be reproduced in its current systems. In response to questions about recurrence, Telia clarified that it implemented a pre-check around July 2018 to prevent enrollment for the forbidden values, and that post-issuance linting is used to find previously unknown issues only. The bug was marked RESOLVED with resolution FIXED, and a later comment stated that remediation appeared to be completed.

Model: gpt-5.4-nano Generated: 2026-06-13 18:03 UTC Revised: 2026-06-16 18:14 UTC Confidence: 0.86 7 comments
Chronology
  1. Telia performed a mass lint scan of its SSL certificates and discovered nine invalid certificates, including three with an invalid OU value "-".
  2. Telia revoked the affected certificates after preliminary analysis.
  3. Telia completed quick analysis and began root cause analysis of the OU verification issue.
  4. A comment indicated remediation had been completed.
Thread Activity
  1. Teliasonera representative — Reported that Telia’s mass lint scan found nine invalid certificates, including three with invalid OU value "-", and described the incident and Telia’s response steps.
  2. Fastly representative — Asked whether Telia had not prevented recurrence because linting is done post-issuance, and how Telia would prevent the issue from happening again.
  3. Teliasonera representative — Clarified that a pre-check implemented around July 2018 prevents enrollment for the forbidden OU values, and that only certificates created before that timestamp may have the issue.
  4. Tds representative — Posted links to crt.sh queries for the certificates referenced in the thread.
  5. Mozilla representative — Corrected the bug type to a task.
  6. Fastly representative — Commented that remediation has been completed.
Participants
Teliasonera representative Fastly representative Tds representative Mozilla representative
Similar Local Cases
#1528261 RESOLVED Certificate Misissuance Opened 2019-02-15 · Closed 2023-02-22 · 100% similar
Telia: Misissued certificate - FQDN without domain part (e_dnsname_not_valid_tld)
#1528263 RESOLVED Certificate Misissuance Opened 2019-02-15 · Closed 2023-02-22 · 100% similar
Telia: Misissued certificate - Invalid wildcard format
#1524050 RESOLVED Certificate Misissuance Opened 2019-01-30 · Closed 2023-02-22 · 96% similar
Telia: Misissued certificate - invalid dnsName
#1524567 RESOLVED Certificate Misissuance Opened 2019-02-01 · Closed 2023-02-22 · 95% similar
Telia: invalid IP value in SAN DNS field
#1528259 RESOLVED Certificate Misissuance Opened 2019-02-15 · Closed 2023-02-22 · 93% similar
Telia: misissued certificate - FQDN value incorrectly in SAN rfc822 field
#1828105 RESOLVED Certificate Misissuance Opened 2023-04-14 · Closed 2023-06-30 · 90% similar
Telia: Misissued certificate - wrong OrganizationName value "Hair 8 Brains"
#1738207 RESOLVED Certificate Misissuance Opened 2021-10-28 · Closed 2023-02-22 · 88% similar
Telia: Issued three precertificates with non-NIST EC curve
#1969036 RESOLVED Certificate Misissuance Opened 2025-05-28 · Closed 2025-10-31 · 83% similar
Telia: TLS incorrect AIA caIssuer URI and incorrect CDP

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action