← Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert) cases
Bugzilla #1590723
Certificate Misissuance
Consorci AOC: Misissued certificates: commonName:organizationIdentifier attribute inclusion not conforming CABForum guidelines 1.6.9
RESOLVED
FIXED
Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert)
AI Summary
Consorci AOC reported the issuance of 19 SSL certificates that included the subject:organizationIdentifier attribute, which did not comply with CABForum guidelines version 1.6.9. The issue was identified during an internal audit on October 9, 2019, and the CA took steps to revoke the affected certificates. All 19 certificates were revoked by November 27, 2019. The CA has since ceased issuing new SSL certificates and plans to ensure compliance with future guidelines.
Chronology
- Internal audit identified misissued certificates.
- Identified applicable versions of EV Guidelines and affected certificates.
- Planned revocation of affected certificates.
- Publicly notified issue to Bugzilla.
- All affected certificates revoked.
Participants
Francesc Ferrer
External References
Similar Local Cases
Telia: S/MIME Misissuance - incorrect subject information for Multipurpose sponsor-validated-profile
DigiCert: SMIME certificates issued inconsistent with BR’s
Trustis: Certificate not version 3
Izenpe: Multiple invalid EV certificates issued
IdenTrust: Improper encoding of wildcard certificate
eMudhra emSign PKI Services : www Subdomain Inclusion in Certificate SAN via ACME Issuance Workflow
OATI: Misissuance detected by PKIMetal
DigiCert: CAA processing during network disruption