← Telia Company cases
Bugzilla #1551372 Certificate Misissuance

Telia: "Some-State" in stateOrProvinceName

RESOLVED FIXED Telia Company
AI Summary

Telia Company reported a certificate misissuance where a certificate contained the stateOrProvinceName value of "Some-State", which was not properly validated according to the Baseline Requirements. The issue was identified on May 11, 2019, and Telia took corrective actions, including revocation of the certificate and an incident report submission. The company has since ceased using the state attribute in their certificates and implemented new validation processes to prevent similar issues in the future. However, concerns were raised regarding the adequacy of their incident response and validation processes.

Model: gpt-4o-mini Generated: 2026-06-13 18:13 UTC Confidence: 0.80
Chronology
  1. Telia received a report about the invalid ST value.
  2. The problematic certificate was replaced and revoked.
  3. Concerns about the adequacy of Telia's validation processes were raised.
  4. Telia identified additional invalid locality values during further review.
  5. Telia provided updates on their incident response improvements.
Participants
Wayne Thayer Pekka Lahtiharju Ryan Sleevi
External References
Similar Local Cases
#1524050 RESOLVED Certificate Misissuance Opened 2019-01-30 · Closed 2023-02-22 · 76% similar
Telia: Misissued certificate - invalid dnsName
#1563575 RESOLVED Certificate Misissuance Opened 2019-07-04 · Closed 2023-02-22 · 73% similar
Telia: Failure to disclose Unconstrained Intermediate within 7 Days
#1520299 RESOLVED Certificate Misissuance Opened 2019-01-15 · Closed 2023-02-22 · 61% similar
Hongkong Post / Certizen: Failure to report misissuance
#1644936 RESOLVED Certificate Misissuance Opened 2020-06-11 · Closed 2024-05-09 · 60% similar
Microsoft PKI Services: Certificate Mis-Issuance, Locality Missing
#1551363 RESOLVED Certificate Misissuance Opened 2019-05-14 · Closed 2023-02-22 · 60% similar
DigiCert: "Some-State" in stateOrProvinceName
#1551364 RESOLVED Certificate Misissuance Opened 2019-05-14 · Closed 2023-02-22 · 60% similar
SwissSign: "Some-State" in stateOrProvinceName
#1523186 RESOLVED Certificate Misissuance Opened 2019-01-27 · Closed 2023-02-22 · 60% similar
KIR S.A.: Misissuance - missing OCSP AIA, Validity > 825 days
#1611458 RESOLVED Certificate Misissuance Opened 2020-01-24 · Closed 2023-02-22 · 59% similar
Asseco DS / Certum: Invalid value in SAN dNSName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action