← SwissSign AG cases
Bugzilla #1558552
Certificate Problem Report
SwissSign: CP/CPS certificate profile issue
RESOLVED
FIXED
SwissSign AG
AI Summary
SwissSign AG reported a certificate profile issue related to their CP/CPS documentation, which led to the issuance of certificates with incorrect OIDs. The problem was identified through internal audits and external reports, prompting a thorough investigation. SwissSign confirmed that no EV certificates were affected and that the misissued certificates did not pose a security risk. A comprehensive revocation plan was implemented, resulting in the revocation of over 72,000 certificates by the end of 2019. The company has since improved its processes to prevent similar issues in the future.
Chronology
- Initial report of CP/CPS certificate profile issue.
- SwissSign outlines revocation plan for misissued certificates.
- Additional misissued certificates identified.
- Confirmation that all affected certificates have been revoked or expired.
Participants
Mike Guenther
Ryan Sleevi
Wayne Thayer
Timo Schmitt
Nathalie Weiler
External References
Similar Local Cases
SwissSign: Delayed revocation for mispellings in Location for a number of Certificates
SwissSign: duplicate serial number
SwissSign: Invalid stateOrProvinceName field
SwissSign: duplicate serial number
SwissSign: Error in OrganisationIdentifier in signature/seal certificate
SwissSign: Certificate issue with Signature
SwissSign: 'c/o' in streetAddress of EV certificate
QuoVadis: N/A in EV serialNumber field