← Government of Turkey, Kamu Sertifikasyon Merkezi (Kamu SM) cases
Bugzilla #1551369 Certificate Misissuance

Kamu SM: "Some-State" in stateOrProvinceName

RESOLVED FIXED Government of Turkey, Kamu Sertifikasyon Merkezi (Kamu SM)
AI Summary

The Government of Turkey's Kamu Sertifikasyon Merkezi (Kamu SM) issued two certificates containing the invalid stateOrProvinceName "Some-State" due to a failure in validating the CSR fields. This issue was identified through a notification from the Mozilla community, leading to an investigation that confirmed only the two certificates were affected. Kamu SM has since implemented controls in their ARMA system to prevent such misissuances in the future, including the addition of validation for the state and locality fields. The problematic certificates have been revoked, and remediation measures are now in place.

Model: gpt-4o-mini Generated: 2026-06-13 18:13 UTC Confidence: 0.95
Chronology
  1. Kamu SM became aware of the issue via a notification.
  2. Revocation of the two problematic certificates was completed.
  3. Controls on the CSR subject field were added to the ARMA program.
  4. All questions were answered and remediation was confirmed complete.
Participants
Wayne Thayer Melis Şimşek Ryan Sleevi Erhan Turan
Similar Local Cases
#1582601 RESOLVED Certificate Misissuance Opened 2019-09-20 · Closed 2023-02-22 · 60% similar
E-Tugra: Invalid DER results in failure to comply with RFC 5280 - Violating string length limit
#1548714 RESOLVED Certificate Misissuance Opened 2019-05-02 · Closed 2023-02-22 · 60% similar
SECOM: "Default City" in Subject:localityName
#1520299 RESOLVED Certificate Misissuance Opened 2019-01-15 · Closed 2023-02-22 · 60% similar
Hongkong Post / Certizen: Failure to report misissuance
#1551363 RESOLVED Certificate Misissuance Opened 2019-05-14 · Closed 2023-02-22 · 59% similar
DigiCert: "Some-State" in stateOrProvinceName
#1428877 RESOLVED Certificate Misissuance Opened 2018-01-08 · Closed 2023-02-22 · 59% similar
SwissSign: Invalid DNSName in SAN
#1462423 RESOLVED Certificate Misissuance Opened 2018-05-17 · Closed 2023-02-22 · 59% similar
NetLock: CN not in SAN
#1563574 RESOLVED Certificate Misissuance Opened 2019-07-04 · Closed 2023-02-22 · 58% similar
SECOM: Failure to disclose Unconstrained Intermediate within 7 Days
#1551375 RESOLVED Certificate Misissuance Opened 2019-05-14 · Closed 2023-02-22 · 58% similar
certSIGN: "Some-State" in stateOrProvinceName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action