← SwissSign AG cases
Bugzilla #1551364
Certificate Misissuance
SwissSign: "Some-State" in stateOrProvinceName
RESOLVED
FIXED
SwissSign AG
AI Summary
SwissSign AG reported a misissuance of a certificate containing 'Some-State' in the stateOrProvinceName field, which is a default value in OpenSSL CSRs and was not validated. This misissuance violated BR section 7.1.4.2.2(f), which requires the field to contain verified state or province information. The issue was identified on May 13, 2019, and the certificate was revoked within 24 hours. SwissSign has since improved their RAO checklists and conducted additional training to prevent future occurrences.
Chronology
- SwissSign became aware of the misissuance via a post in mozilla.dev.security.policy.
- Certificate was revoked and an incident report was published.
Participants
Wayne Thayer
Timo Schmitt
Ryan Sleevi
External References
Similar Local Cases
SwissSign: Misissuance with mispellings in Location for a number of Certificates
SwissSign: Invalid DNSName in SAN
SwissSign: Misissuance of Leaf Certificates because of incorrect postcode
certSIGN: "Some-State" in stateOrProvinceName
DigiCert: "Some-State" in stateOrProvinceName
Telia: "Some-State" in stateOrProvinceName
SwissSign: Cert issued with a to long validity period
Hongkong Post / Certizen: Failure to report misissuance