← e-tugra cases
Bugzilla #1582601 Self Reported Incident Certificate Misissuance

E-Tugra: Invalid DER results in failure to comply with RFC 5280 (country name length limit)

RESOLVED FIXED e-tugra
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns E-Tugra certificates that were incompatible with RFC 5280 due to invalid country name encoding/character data and an overlong country name. The issue was identified after a prior Mozilla CA Program incident report in Bug 1462797, and Ryan Sleevi noted that the specific certificate in this bug was issued on 2018-09-12 and was not revoked at the time of the initial report. Davut Tokgöz stated they were investigating the miscompliance and later provided an incident report describing how E-Tugra became aware of the problem via Bugzilla and how they tested historical certificates. E-Tugra reported that it rebuilt its RFC 5280 compliance controls in January 2019, then tested certificates and discovered additional certificates issued incompatible with RFC 5280, which were replaced and revoked. E-Tugra also stated that as of September 30, no more certificates were found in its systems with the problem, and as of January 31 no more certificates would be produced with these problems. The thread concludes with a comment indicating that remediation is complete and that questions were answered.

Model: gpt-5.4-nano Generated: 2026-06-13 20:00 UTC Revised: 2026-06-16 18:32 UTC Confidence: 0.86 8 comments
Chronology
  1. E-Tugra issued a certificate later identified as incompatible with RFC 5280 due to country name issues.
  2. E-Tugra reported rebuilding RFC 5280 compliance controls and completing remediation for the related control issues.
  3. E-Tugra reported finding no further certificates in its systems with the RFC 5280 incompatibility.
  4. E-Tugra indicated remediation was complete and that questions had been answered.
Thread Activity
  1. Community commenter — Reported that E-Tugra issued a certificate with an invalid, overlong country name per RFC 5280 and noted it was not revoked at the time.
  2. Community commenter — Asked why the certificate was not previously detected and what steps E-Tugra was taking to examine historical issuance against current controls.
  3. E-Tugra — Said he was investigating the miscompliance and would provide a report soon.
  4. E-Tugra — Provided an incident report describing awareness, testing of certificates, replacement/revocation, and remediation steps (including an Excel report link).
  5. Fastly representative — Requested an update explaining how certificates would not be missed in future investigations beyond the specific incident.
  6. E-Tugra — Provided an updated report including additional internal procedure instructions to avoid missing similar certificates.
  7. Fastly representative — Indicated it appears all questions were answered and remediation is complete.
Participants
Community commenter E-Tugra Fastly representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1542302 RESOLVED Self Reported Incident Opened 2019-04-05 · Closed 2023-02-22 · 83% similar
E-Tugra: Insufficient serial number entropy
#1687139 RESOLVED Self Reported Incident Opened 2021-01-16 · Closed 2023-02-22 · 78% similar
E-Tugra: commonName not in SAN
#1801345 RESOLVED Self Reported Incident Security Incident Opened 2022-11-18 · Closed 2023-07-21 · 78% similar
E-Tugra: Incident Report (Security Issues)
#1539358 RESOLVED Self Reported Incident Opened 2019-03-27 · Closed 2023-02-22 · 76% similar
SECOM: Insufficient Serial Number Entropy
#1544722 RESOLVED Self Reported Incident Opened 2019-04-16 · Closed 2023-02-22 · 76% similar
SECOM: certificate for which “L” and “ST” not set
#1449371 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2018-03-27 · Closed 2023-02-22 · 76% similar
E-Tugra: Validity period > 825 days
#1841534 RESOLVED Self Reported Incident Certificate Misissuance Opened 2023-07-03 · Closed 2023-08-30 · 73% similar
Apple: TLS certificates issued outside the TTL of the CAA record
#1731586 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Opened 2021-09-20 · Closed 2023-02-22 · 72% similar
SwissSign: Certificate with key length 16258

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action