← SwissSign AG cases
Bugzilla #1613334
Certificate Misissuance
SwissSign: Misissuance with mispellings in Location for a number of Certificates
RESOLVED
FIXED
SwissSign AG
AI Summary
SwissSign AG reported a misissuance incident involving 47 SSL and 113 S/MIME certificates due to misspellings in the location field. The issue was identified during an audit, leading to the revocation of the affected certificates. SwissSign implemented a manual process to prevent future misissuance and has since worked on automating checks against official standards. The incident raised concerns about timely reporting and revocation, which SwissSign acknowledged and addressed in subsequent communications.
Chronology
- Last certificates delivered for analysis.
- Misissue acknowledged and revocation triggered.
- Incident report posted.
- New automation for checks implemented.
- All affected certificates revoked.
Participants
Nathalie Weiler
Mike Guenther
Ryan Sleevi
Wayne Thayer
Ben Wilson
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
SwissSign: Invalid DNSName in SAN
SwissSign: Mis-Issuance of S/MIME certificates
SwissSign: Misissuance of Leaf Certificates because of incorrect postcode
SwissSign: Certificate with key length 4098 bit
SwissSign: Misissuance of Intermediate Certificates because of incorrect organizationIdentifier
Microsoft PKI Services: Certificate Mis-Issuance, Locality Missing
SwissSign: "Some-State" in stateOrProvinceName
SwissSign: Certificate with key length 16258