← MULTICERT cases
Bugzilla #1637093 Validation Issue

Multicert: AIA CA Issuer field pointing to PEM encoded cert

RESOLVED FIXED MULTICERT
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Multicert discovered that the CA certificate file linked in the Authority Information Access (AIA) of its end entity certificates was incorrectly encoded in PEM format instead of the required DER format. This issue was reported to Multicert via email on May 11, 2020. Upon confirmation of the incident, Multicert promptly replaced the CA certificate file with the correct DER encoded version in their public repository. The CA continued issuing certificates as the issue did not result in any misissuance or require revocation of end user certificates. Multicert updated its procedures to ensure future compliance with the DER format requirement.

Model: gpt-4o-mini Generated: 2026-06-13 21:11 UTC Revised: 2026-06-16 19:13 UTC Confidence: 0.85 12 comments
Chronology
  1. Multicert received a notification about the incorrect encoding of the CA certificate.
  2. Multicert replaced the CA certificate file with the correct DER encoded version.
Thread Activity
  1. MULTICERT — Multicert reported the discovery of the PEM encoding issue and the steps taken to resolve it.
  2. Mozilla representative — Inquired about testing the updated procedure for publishing CA certificates in DER format.
  3. MULTICERT — Explained the monitoring setup for continuous compliance with the DER format requirement.
  4. Mozilla representative — Indicated intent to close the bug unless further comments were received.
Participants
MULTICERT Mozilla representative Community commenter
Similar Local Cases
#1693304 RESOLVED Validation Issue Opened 2021-02-17 · Closed 2023-02-22 · 75% similar
FNMT: Issuance of QCP-n certificates without verifying identity
#1575880 RESOLVED Self Reported Incident Revocation Issue Validation Issue Opened 2019-08-22 · Closed 2023-02-22 · 74% similar
GlobalSign: SSL Certificates with US country code and invalid State/Prov
#1876593 RESOLVED Validation Issue Revocation Issue Opened 2024-01-25 · Closed 2024-06-06 · 67% similar
Google Trust Services: Failure to properly validate IP address
#1944815 RESOLVED Self Reported Incident Validation Issue Opened 2025-01-30 · Closed 2026-06-10 · 66% similar
GlobalSign: Organization-validated SMIME certificate with invalid organizationIdentifier for European country
#1666872 RESOLVED Validation Issue Opened 2020-09-23 · Closed 2023-02-22 · 65% similar
SSL.com: Insufficient validation evidence for the localityName attribute of an OV certificate
#1917459 RESOLVED Validation Issue Opened 2024-09-08 · Closed 2025-02-14 · 65% similar
eMudhra emSign PKI Services : OCSP Responder Time Inconsistency
#1509002 RESOLVED Self Reported Incident Opened 2018-11-21 · Closed 2023-02-22 · 60% similar
Camerfirma: MULTICERT certificates with a validity period greater than 825 days
#1534429 RESOLVED Ca Certificate Compliance Self Reported Incident Incident Certificate Misissuance Opened 2019-03-11 · Closed 2023-02-22 · 60% similar
Camerfirma: Multicert SSL CA 001: Insufficient serial number entropy

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action