← SwissSign AG cases
Bugzilla #1506607
Certificate Misissuance
SwissSign: Misissuance of Intermediate Certificates because of incorrect organizationIdentifier
RESOLVED
FIXED
SwissSign AG
AI Summary
SwissSign AG reported a misissuance of six intermediate certificates due to an incorrect organizationIdentifier. The error was discovered during an internal review on November 9, 2018, leading to an immediate internal incident management process. The organizationIdentifier was incorrectly documented as 'FL-0002.523.017-8' instead of the correct 'NTRLI-FL-0002.523.017-8'. No leaf certificates were affected, as the intermediate certificates had not yet been used for production. SwissSign has since implemented corrective measures and technical safeguards to prevent future occurrences.
Chronology
- Issue detected during internal review
- Root cause analysis initiated
- Technical safeguard successfully deployed
Participants
Mike Guenther
W. Thayer
Ryan Sleevi
External References
Similar Local Cases
SwissSign: Misissuance of Leaf Certificates because of incorrect postcode
SwissSign: Invalid DNSName in SAN
SwissSign: Domain validated certificate but with stateOrProvinceName
SwissSign: "Some-State" in stateOrProvinceName
E-Tugra: Improper DER results in failure to comply with RFC 5280 - Invalid characters in PrintableString
Entrust: Certificate Issued with Incorrect Country Code
Amazon Trust Services: No Space In Private Organization
Entrust: Late mis-issue certificate revocation