certSIGN: stateOrProvinceName "Some-State" in issued certificate
This case concerns a certSIGN certificate that contained a subject stateOrProvinceName value of "Some-State". The issue was triggered by the fact that the value appears to be the default placed in OpenSSL CSRs, and certSIGN’s RA officers failed to validate the stateOrProvinceName field as required by the referenced Baseline Requirements. certSIGN discovered the problem via its problem reporting mechanism after receiving an email on r**********n@certsign.ro, identified one affected certificate on https://misissued.com/batch/53/, and revoked the certificate the day after it was published. In its incident report, certSIGN attributed the cause to human error and insufficient technical controls for subject field data validation, noting that no technical control checked for the default contents. certSIGN implemented technical controls to check for the default value in stateOrProvinceName="Some-State" and L="Default City", and later developed and deployed a new CSR checker update that uses ISO 3166-2 to show an error in the interface when stateOrProvinceName is incorrect. The thread indicates remediation was complete after the production deployment of the update.
- certSIGN received an email via its problem reporting mechanism indicating an issue with a certificate subject field value.
- certSIGN finalized its investigation and identified the cause as human error and insufficient technical controls, and began implementing remediation.
- certSIGN deployed an updated CSR checker in production to validate stateOrProvinceName using ISO 3166-2.
- Community commenter — Reported that a certSIGN certificate with stateOrProvinceName "Some-State" was published at https://misissued.com/batch/53/ and requested an incident report, noting the field was not validated per the Baseline Requirements.
- Community commenter — Submitted an incident report describing how certSIGN became aware of the problem, the timeline, the cause (human error and insufficient technical controls), and remediation steps including new technical controls.
- Community commenter — Asked for clarification on why an initial incident report was not filed/acknowledged sooner and challenged whether proposed controls addressed the root cause, requesting analysis of related bugs.
- Community commenter — Explained the acknowledgment timing, described existing controls (CSR checker and CAB certificate linter), and stated that rejecting defaults automatically was their interim solution due to lack of an authoritative source.
- Community commenter — Requested an update on certSIGN’s analysis of controls from the related bugs, including authoritative state/province sources.
- Community commenter — Stated certSIGN was developing a new CSR checker control based on ISO 3166-2 and planned to deploy it by July 25.
- Community commenter — Reported that the CSR checker update was deployed to the production environment.
- Community commenter — Confirmed that it appeared all questions were answered and remediation was complete.