← Swisscom (Switzerland) Ltd cases
Bugzilla #1195115
Certificate Problem Report
Swisscom: certificates without DNS names in subjectAltName
RESOLVED
Swisscom (Switzerland) Ltd
AI Summary
Swisscom, an EV-qualified CA, was found to be issuing SSL certificates that lacked DNS names in the subjectAltName field, relying solely on the Common Name for validation. This practice violates CAB Forum Baseline Requirements. Although Swisscom acknowledged the issue and committed to corrective actions, they continued to issue such certificates for an extended period. Ultimately, Swisscom ceased issuing SSL certificates altogether, leading to the resolution of this case.
Chronology
- Bug reported regarding SSL certificates without DNS names.
- Swisscom acknowledged the issue and outlined corrective actions.
- Swisscom announced they would stop issuing SSL certificates.
- Case suggested for closure due to cessation of certificate issuance.
Participants
H-P Waldegger
Adm Selec
Kathleen Wilson
External References
Similar Local Cases
Hongkong Post e-Cert CA 1 - 10 issuing certificates without subject alternative name extension
DigiCert: ECCE 001 issuing certificates without subject alternative name extension
StartCom: public exponent is 1
D-Trust: issuing 1024 bit certificates
Camerfirma: certs with duplicate SANs and without localityName or stateOrProvinceName
LuxTrust: issuing 1024 bit certificates
Swisscom: valid 512 bit certificate
Let's Encrypt: Non-BR-Compliant Certificate Issuance