← Telia Company cases
Bugzilla #1528264
Certificate Misissuance
Telia: Misissued certificate - Invalid OU value "-"
RESOLVED
FIXED
Telia Company
AI Summary
Telia Company reported a misissuance of SSL certificates due to an invalid Organizational Unit (OU) value of "-". This issue was discovered during a mass lint scan conducted on February 8, 2019, which identified nine invalid certificates across various error categories. The CA took immediate action by revoking the affected certificates within the required timeframe. A root cause analysis revealed a bug in the OU verification code, which has since been fixed. Telia has implemented pre-checks to prevent similar issues from occurring in the future.
Chronology
- Discovery of invalid certificates during mass lint scan
- Preliminary analysis and decision to revoke certificates
- Quick analysis confirmed the issue could not be reproduced
- Root cause analysis completed
Participants
pekka.lahtiharju@teliasonera.com
wthayer@fastly.com
bugzilla@tds.xyz
bug-husbandry-bot@mozilla.bugs
External References
Similar Local Cases
Telia: Misissued certificate - Invalid wildcard format
Telia: Misissued certificate - FQDN without domain part (e_dnsname_not_valid_tld)
Telia: invalid IP value in SAN DNS field
Telia: misissued certificate - FQDN value incorrectly in SAN rfc822 field
Telia: Ambiguity on KeyUsage with ECC public key
Telia: Misissued certificate - wrong OrganizationName value "Hair 8 Brains"
Telia: Non-BR-Compliant OCSP Responder
Telia: TLS certificates issued in violation of TLS BR v2.0.1