← certSIGN cases
Bugzilla #1551375 Certificate Misissuance

certSIGN: stateOrProvinceName "Some-State" in issued certificate

RESOLVED FIXED certSIGN
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns a certSIGN certificate that contained a subject stateOrProvinceName value of "Some-State". The issue was triggered by the fact that the value appears to be the default placed in OpenSSL CSRs, and certSIGN’s RA officers failed to validate the stateOrProvinceName field as required by the referenced Baseline Requirements. certSIGN discovered the problem via its problem reporting mechanism after receiving an email on r**********n@certsign.ro, identified one affected certificate on https://misissued.com/batch/53/, and revoked the certificate the day after it was published. In its incident report, certSIGN attributed the cause to human error and insufficient technical controls for subject field data validation, noting that no technical control checked for the default contents. certSIGN implemented technical controls to check for the default value in stateOrProvinceName="Some-State" and L="Default City", and later developed and deployed a new CSR checker update that uses ISO 3166-2 to show an error in the interface when stateOrProvinceName is incorrect. The thread indicates remediation was complete after the production deployment of the update.

Model: gpt-5.4-nano Generated: 2026-06-13 18:13 UTC Revised: 2026-06-16 18:21 UTC Confidence: 0.86 8 comments
Chronology
  1. certSIGN received an email via its problem reporting mechanism indicating an issue with a certificate subject field value.
  2. certSIGN finalized its investigation and identified the cause as human error and insufficient technical controls, and began implementing remediation.
  3. certSIGN deployed an updated CSR checker in production to validate stateOrProvinceName using ISO 3166-2.
Thread Activity
  1. Community commenter — Reported that a certSIGN certificate with stateOrProvinceName "Some-State" was published at https://misissued.com/batch/53/ and requested an incident report, noting the field was not validated per the Baseline Requirements.
  2. Community commenter — Submitted an incident report describing how certSIGN became aware of the problem, the timeline, the cause (human error and insufficient technical controls), and remediation steps including new technical controls.
  3. Community commenter — Asked for clarification on why an initial incident report was not filed/acknowledged sooner and challenged whether proposed controls addressed the root cause, requesting analysis of related bugs.
  4. Community commenter — Explained the acknowledgment timing, described existing controls (CSR checker and CAB certificate linter), and stated that rejecting defaults automatically was their interim solution due to lack of an authoritative source.
  5. Community commenter — Requested an update on certSIGN’s analysis of controls from the related bugs, including authoritative state/province sources.
  6. Community commenter — Stated certSIGN was developing a new CSR checker control based on ISO 3166-2 and planned to deploy it by July 25.
  7. Community commenter — Reported that the CSR checker update was deployed to the production environment.
  8. Community commenter — Confirmed that it appeared all questions were answered and remediation was complete.
Participants
Community commenter
Similar Local Cases
#1398243 RESOLVED Certificate Misissuance Opened 2017-09-08 · Closed 2023-02-22 · 80% similar
certSIGN: Non-BR-Compliant OCSP Responders
#1531817 RESOLVED Certificate Misissuance Opened 2019-03-01 · Closed 2023-02-22 · 68% similar
DigiCert: in-addr.arpa Misissuance
#1436173 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2018-02-06 · Closed 2023-02-22 · 68% similar
DigiCert: SCEE / Justica: Non-BR-Compliant Certificate Issuance
#1538673 RESOLVED Certificate Misissuance Opened 2019-03-25 · Closed 2023-02-22 · 67% similar
Consorci AOC: EC-SECTORPUBLIC insufficient serial number entropy
#1744722 RESOLVED Certificate Misissuance Opened 2021-12-07 · Closed 2023-02-22 · 63% similar
FNMT: Invalid localityName
#1524730 RESOLVED Certificate Misissuance Revocation Issue Opened 2019-02-02 · Closed 2023-02-22 · 62% similar
Sectigo: invalid dnsName
#1763173 RESOLVED Certificate Misissuance Opened 2022-04-05 · Closed 2023-02-22 · 62% similar
certSIGN: Incorrect data in stateOrProvinceName
#1462797 RESOLVED Certificate Misissuance Opened 2018-05-18 · Closed 2023-02-22 · 61% similar
E-Tugra: Improper DER results in failure to comply with RFC 5280 - Invalid characters in PrintableString

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action