← eMudhra Technologies Limited cases
Bugzilla #1665688
Certificate Misissuance
eMudhra: emSign CA ECC Test Certificate Misissuance
RESOLVED
FIXED
eMudhra Technologies Limited
AI Summary
eMudhra Technologies Limited reported a misissuance of SSL/TLS certificates using the ECC algorithm, which incorrectly included key usage for key encipherment. The issue was identified on September 10, 2020, and was limited to four active test certificates. The CA took immediate corrective actions, including revoking the problematic certificates and updating their issuance procedures to prevent future occurrences. The incident was resolved with no impact on external customers, as the affected certificates were only for internal testing.
Chronology
- Configurations made for generating test certificates.
- Problem reported regarding key usage issue.
- New test certificates issuance completed and verified.
- Incident analysis reviewed.
- Analysis of misissuance completed.
Participants
Vijay Kumar
Ben Wilson
Ryan Sleevi
External References
Similar Local Cases
eMudhra: emSign CA Invalid AIA Extension Value
eMudhra: emSign CA Invalid OrganizationalUnitName
Izenpe: certificate issued to internal domain
Sectigo: Incorrect JOI for federal credit unions
IdenTrust: Validation Source for EV Certificates not Publicly Disclosed
SwissSign: Misissuance with mispellings in Location for a number of Certificates
NetLock: Issuance of >398-day precertificates after 2020-09-01
Microsoft PKI Services: Certificate Mis-Issuance, Locality Missing