← eMudhra Technologies Limited cases
Bugzilla #1665688 Certificate Misissuance

eMudhra: emSign CA ECC test certificate misissuance (incorrect Key Usage)

RESOLVED FIXED eMudhra Technologies Limited
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The case reports that eMudhra’s emSign CA issued SSL/TLS certificates using ECC that contained an incorrect Key Usage value (keyEncipherment). The CA stated it became aware of the problem through a report received on 10-Sep-2020 09:19 (Indian Time). The CA said the impacted certificates were limited to test certificates used for its test websites (and other test certificates that were part of revoked and expired URLs), and that it flagged the incident as non-critical with no impact to external customers. In response, the CA made system changes to correct the certificate issuance configuration, restarted issuance of new test certificates, and completed independent lint tests. The CA also completed revocations and stated that misissuance analysis was completed, with the problematic certificates first issued between 21-Aug-2020 and last issued on 28-Aug-2020 (24 problematic certificates total, including 20 already revoked/expired prior to notice, and 4 active that were revoked). Mozilla indicated it intended to close the incident unless there were further questions, and the CA provided additional explanation addressing concerns about the incident report’s detail. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:20 UTC Revised: 2026-06-16 18:28 UTC Confidence: 0.86 6 comments
Chronology
  1. eMudhra configured its certificate issuance procedure for generating test certificates for test URLs.
  2. eMudhra issued the first set of ECC test certificates.
  3. eMudhra revoked test certificates as part of CT log server configuration changes.
  4. eMudhra received a problem report about the incorrect Key Usage in ECC test certificates and began analysis.
  5. eMudhra flagged the incident and made system changes to correct the issuance configuration.
  6. eMudhra completed issuance and verification of new test certificates and completed test URL configuration.
  7. eMudhra completed incident analysis review.
  8. eMudhra completed revocations for the problematic certificates.
  9. eMudhra completed misissuance analysis.
Thread Activity
  1. Emudhra representative — Vijay Kumar disclosed that ECC SSL/TLS test certificates were issued with Key Usage set to keyEncipherment, described the CA’s timeline, and listed CT links for the problematic certificates.
  2. Mozilla representative — Ben Wilson thanked the CA for the disclosure and said he intended to close the incident on or about 9-Oct-2020 unless questions remained.
  3. Community commenter — Ryan Sleevi requested more detailed incident-report information, questioning the sufficiency of the explanation and the framing of impact as internal-only.
  4. Mozilla representative — Ben Wilson asked Vijay to respond to Ryan’s questions and comments.
  5. Emudhra representative — Vijay responded with additional explanation, stating the issue was due to misconfiguration/oversight for test certificates and that procedures were updated with additional verification and linting coverage.
  6. Mozilla representative — Ben Wilson pushed closure out by another week, setting a tentative closure date of 16-Oct-2020.
Participants
Emudhra representative Mozilla representative Community commenter
Similar Local Cases
#1745015 RESOLVED Certificate Misissuance Opened 2021-12-08 · Closed 2023-02-22 · 82% similar
eMudhra: emSign CA Invalid OrganizationalUnitName
#1763700 RESOLVED Certificate Misissuance Opened 2022-04-07 · Closed 2023-02-22 · 82% similar
eMudhra: emSign CA Invalid AIA Extension Value
#2043837 ASSIGNED Ca Certificate Compliance Certificate Misissuance Validation Issue Revocation Issue Opened 2026-05-30 Still Open · 70% similar
eMudhra emSign PKI Services: www Subdomain Inclusion in Certificate SAN via ACME Issuance Workflow
#1860697 RESOLVED Certificate Misissuance Opened 2023-10-24 · Closed 2024-01-04 · 69% similar
DigiCert: Certificates issued inconsistent with S/MIME BR v1.0.1
#1649942 RESOLVED Certificate Misissuance Opened 2020-07-02 · Closed 2023-02-22 · 68% similar
SK ID Solutions: Incorrect OCSP Delegated Responder Certificate
#1398243 RESOLVED Certificate Misissuance Opened 2017-09-08 · Closed 2023-02-22 · 68% similar
certSIGN: Non-BR-Compliant OCSP Responders
#1728384 RESOLVED Certificate Misissuance Incident Opened 2021-08-31 · Closed 2023-02-22 · 64% similar
Microsec: Misissuance of one OV certificate with Key Usage KeyEncipherment
#1654216 RESOLVED Certificate Misissuance Opened 2020-07-21 · Closed 2023-02-22 · 64% similar
Buypass: PSD2 QWAC with RSA modulus not divisible by 8

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action