← Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert) cases
Bugzilla #1590723 Certificate Misissuance Self Reported Incident

Consorci AOC: Misissued EV certificates included subject:organizationIdentifier attribute (CABForum EV Guidelines 1.6.9 non-compliance)

RESOLVED FIXED Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Consorci AOC reported that, during its quarterly internal audits, it detected a compliance issue affecting EV SSL certificates issued under the EV Guidelines version 1.6.9. The issue was that 19 certificates issued under the EV Guidelines (within the validity period of version 1.6.9) incorrectly contained the subject:organizationIdentifier attribute. Consorci AOC stated that it identified the applicable EV Guidelines versions and affected certificates on 2019-10-11, planned revocation on 2019-10-16, and publicly notified the issue to Bugzilla on 2019-10-23. The CA said the scope was limited to certificates issued between April 16, 2019 and June 20, 2019, and that the 19 affected certificates were issued between April 24, 2019 and June 18, 2019. Consorci AOC also stated it would cease issuing new SSL certificates by the end of 2019 and would carry out revocation gradually, with renewal of affected certificates planned to be completed by mid-November. In the thread, Consorci AOC later confirmed that the 19 affected certificates have been revoked, and a third party indicated that remediation was complete.

Model: gpt-5.4-nano Generated: 2026-06-13 20:02 UTC Revised: 2026-06-16 18:34 UTC Confidence: 0.90 4 comments
Chronology
  1. Consorci AOC’s Q2 2019 quarterly internal audit detected that 19 EV SSL certificates incorrectly contained the subject:organizationIdentifier attribute.
  2. Consorci AOC identified the applicable EV Guidelines versions and the affected certificates.
  3. Consorci AOC planned revocation of the affected certificates.
  4. Consorci AOC publicly notified the issue to Bugzilla through this incident report.
  5. Consorci AOC revoked the 19 affected certificates.
Thread Activity
  1. Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert) — Reported that 19 EV SSL certificates issued under EV Guidelines 1.6.9 incorrectly included subject:organizationIdentifier, and provided a timeline and CT links.
  2. Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert) — Confirmed that the 19 affected certificates have been revoked.
  3. Fastly representative — Stated that it appears all questions were answered and remediation is complete.
Participants
Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert) Fastly representative
Similar Local Cases
#1473971 RESOLVED Self Reported Incident Certificate Misissuance Opened 2018-07-06 · Closed 2023-02-22 · 79% similar
SwissSign: Domain validated certificate but with stateOrProvinceName
#1599484 RESOLVED Self Reported Incident Certificate Misissuance Opened 2019-11-26 · Closed 2023-02-22 · 79% similar
Entrust: EV Certificates Issued with Business Category "Non-Commercial" when it should have been set to "Private Organization"
#1506607 RESOLVED Self Reported Incident Certificate Misissuance Opened 2018-11-12 · Closed 2026-06-10 · 78% similar
SwissSign: Misissuance of Intermediate Certificates because of incorrect organizationIdentifier
#1599775 RESOLVED Self Reported Incident Certificate Misissuance Opened 2019-11-27 · Closed 2023-02-22 · 78% similar
GlobalSign: Wrong business category (Non Commercial Entity when should have been Private Organization)
#1500621 RESOLVED Certificate Misissuance Self Reported Incident Opened 2018-10-19 · Closed 2023-02-22 · 77% similar
DigiCert: Internal Domain Name cert mis-issuance
#1575022 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2019-08-19 · Closed 2023-02-22 · 77% similar
Sectigo: EV SSL Certificates with incorrect subject details.
#1532113 RESOLVED Certificate Misissuance Self Reported Incident Opened 2019-03-03 · Closed 2023-02-22 · 77% similar
CFCA: O > 64 characters
#1409766 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Opened 2017-10-18 · Closed 2023-02-22 · 77% similar
Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action