SwissSign: Misissuance with misspellings in Location for a number of Certificates
SwissSign AG reported a misissuance incident involving 47 SSL and 113 S/MIME certificates that contained misspellings in the location fields. The issue was discovered during an audit on November 14, 2019, leading to the revocation of the affected certificates starting December 11, 2019. SwissSign implemented a manual process to prevent future misissuance and has since developed automated checks based on official standards. The incident report was filed on February 5, 2020, after the critical certificates were revoked. The CA acknowledged delays in reporting and revocation, which were attributed to the nature of the certificates' use in critical infrastructure. The case has been resolved with all identified certificates revoked.
- Discovery of misissued certificates during an audit.
- Acknowledgment of misissue and initiation of revocation.
- Incident report filed with Mozilla.
- Implementation of new automated checks.
- All affected certificates revoked.
- SwissSign AG — Reported misissuance of certificates with misspellings.
- Mozilla representative — Questioned the delay in filing the incident report.
- Community commenter — Emphasized the need for timely reporting and revocation.
- SwissSign AG — Confirmed implementation of automated checks.
- SwissSign AG — Announced revocation of all affected certificates.