← SwissSign AG cases
Bugzilla #1613406
Certificate Problem Report
SwissSign: Delayed revocation for mispellings in Location for a number of Certificates
RESOLVED
FIXED
SwissSign AG
AI Summary
SwissSign AG faced a situation involving delayed revocation of certificates due to misspellings in the location field. The revocation was initially delayed to avoid impacting critical infrastructure during the holiday season. SwissSign acknowledged the delay in reporting the incident and has since committed to improving their processes to prevent future occurrences. The case highlights the challenges of balancing compliance with operational realities in critical service contexts.
Chronology
- SwissSign acknowledges misissuance and triggers revocation process.
- Revocation performed, except for 5 critical infrastructure certificates.
- Incident report requested by Mozilla.
- SwissSign submits updated incident report.
- SwissSign discusses solutions to improve certificate handling for critical customers.
Participants
Ryan Sleevi
Mike Guenther
Nathalie Weiler
Wayne Thayer
Ben Wilson
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
SwissSign: CP/CPS certificate profile issue
SwissSign: Invalid stateOrProvinceName field
SwissSign: duplicate serial number
Camerfirma: Invalid authorityKeyIdentifier - recurrent incident
SwissSign: Failure to provide a preliminary report within 24 hours.
SwissSign: duplicate serial number
Entrust: S/MIME Certificate Issued with Incorrect Policy OID
SwissSign: Error in OrganisationIdentifier in signature/seal certificate