← Buypass cases
Bugzilla #1632632 Certificate Problem Report

Buypass: Illegal Business Category in a PSD2 QWAC

RESOLVED FIXED Buypass
AI Summary

Buypass reported an incident involving a PSD2 Qualified Website Authentication Certificate (QWAC) that was issued with an incorrect Subject Business Category value of 'UN', instead of the required 'Private Organization'. The issue was identified immediately after issuance, leading to the revocation of the certificate and a halt on issuing similar certificates. Buypass has since implemented stricter controls to prevent such misissuance in the future, including a systematic evaluation of their processes and the introduction of new validation checks.

Model: gpt-4o-mini Generated: 2026-06-13 21:23 UTC Confidence: 1.00
Chronology
  1. PSD2 QWAC issued and illegal value identified.
  2. Certificate revoked and replaced.
  3. Bug fix deployed.
Participants
Mads Henriksveen Ben Wilson Ryan Sleevi
External References
Similar Local Cases
#1654216 RESOLVED Certificate Problem Report Opened 2020-07-21 · Closed 2023-02-22 · 80% similar
Buypass: PSD2 QWAC with RSA modulus not divisible by 8
#1628292 RESOLVED Certificate Problem Report Opened 2020-04-08 · Closed 2023-02-22 · 79% similar
Buypass: Failure to revoke PSD2 QWACs within mandated 5 days
#1626078 RESOLVED Certificate Problem Report Opened 2020-03-30 · Closed 2023-02-22 · 69% similar
Buypass: Missing NCA identifier in cabfOrganizationIdentifier in PSD2 QWACs
#1598319 RESOLVED Certificate Problem Report Opened 2019-11-21 · Closed 2023-02-22 · 67% similar
Buypass: intermediate certificates not revoked within BR time period
#1595113 RESOLVED Certificate Problem Report Opened 2019-11-08 · Closed 2023-02-22 · 66% similar
Buypass: Intermediate certificates not listed in audit reports
#1838421 RESOLVED Certificate Problem Report Opened 2023-06-14 · Closed 2024-06-30 · 64% similar
Buypass: Domain validation method using not allowed domain contact
#1630870 RESOLVED Certificate Problem Report Opened 2020-04-17 · Closed 2023-02-22 · 61% similar
GlobalSign: Certificate issued with RSASSA-PSS public key
#1864204 RESOLVED Certificate Problem Report Opened 2023-11-10 · Closed 2024-05-10 · 60% similar
Buypass: TLS certificates with incorrect Subject attribute order

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action