← Microsec Ltd. cases
Bugzilla #1622539 Self Reported Incident

Microsec: Issuance of 2 IVCP precertificates without givenName, surName, localityName fields

RESOLVED FIXED Microsec Ltd.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Microsec Ltd. reported an incident involving the issuance of two IVCP precertificates that lacked required fields: givenName, surName, and localityName. The CA became aware of the issue through discussions in the mozilla.dev.security.policy mailing list. Upon investigation, Microsec identified that the certificates were issued for internal testing and had already expired, making revocation unnecessary. The CA suspended the issuance of IVCP certificates and implemented corrective measures, including software updates to enforce compliance with certificate profile requirements. As of May 26, 2020, Microsec reactivated the IVCP profiles and resumed issuing IVCP certificates after training their Registration Officers.

Model: gpt-4o-mini Generated: 2026-06-13 21:11 UTC Revised: 2026-06-16 19:12 UTC Confidence: 0.85 12 comments
Chronology
  1. Two precertificates were issued for internal testing purposes.
  2. Microsec was informed about the faulty precertificates.
  3. Microsec activated the new CA software release in the live system.
  4. IVCP profiles were reactivated, allowing the issuance of IVCP certificates again.
Thread Activity
  1. Fastly representative — Dr. Sandor Szoke posted the incident report detailing the compliance failure.
  2. Microsec representative — Microsec completed a review of the CA software for compliance with required fields.
  3. Microsec representative — Microsec provided a status update on the CA software development.
  4. Microsec representative — Microsec announced the reactivation of IVCP profiles.
Participants
Community commenter
Similar Local Cases
#2013576 RESOLVED Self Reported Incident Certificate Misissuance Opened 2026-01-30 · Closed 2026-02-27 · 87% similar
Microsec: "DV valid" test website certificate issued under incorrect root
#2005939 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-12-14 · Closed 2026-03-13 · 82% similar
Microsec: CT Logging mistakes
#1952519 RESOLVED Self Reported Incident Repository Issue Opened 2025-03-07 · Closed 2025-05-08 · 80% similar
Microsec: Inconsistent Disclosure of S/MIME BR Audit Information in CCADB
#1865880 RESOLVED Self Reported Incident Opened 2023-11-21 · Closed 2024-02-14 · 79% similar
Microsec: Findings in 2023 Audit
#1925239 RESOLVED Self Reported Incident Opened 2024-10-17 · Closed 2025-01-14 · 79% similar
Microsec: Expired Certificates on test Pages for Revocation
#1551369 RESOLVED Self Reported Incident Certificate Misissuance Opened 2019-05-14 · Closed 2023-02-22 · 78% similar
Kamu SM: "Some-State" in stateOrProvinceName
#1627346 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Delayed Revocation Opened 2020-04-03 · Closed 2023-02-22 · 78% similar
Entrust: S/MIME Certificate Issued with Incorrect Policy OID
#1684442 RESOLVED Self Reported Incident Opened 2020-12-29 · Closed 2023-02-22 · 77% similar
DigiCert: SHA-1 intermediate issued after 2016-01-01

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action