SwissSign: Invalid stateOrProvinceName field
SwissSign AG faced an issue where one certificate was issued with an invalid 'stateOrProvinceName' field value of 'CH'. This misissuance was alarming as SwissSign had previously assured that no technical constraints were needed for this field. Following the report, an internal investigation was initiated, leading to the revocation of the problematic certificate and the implementation of policies to prevent future occurrences. The root cause was identified as a flaw in their policy search system, which failed to recognize empty fields, resulting in the issuance of certificates without proper constraints.
- Initial report of the issue by George
- Certificate revoked and policies implemented
- All identified certificates revoked