SwissSign: Invalid stateOrProvinceName field
This case reports that SwissSign issued at least one certificate with an invalid value in the stateOrProvinceName field (value "CH"). The issue was identified after SwissSign had previously assured Mozilla in another bug that it did not require technical constraints to limit values in this field. SwissSign initiated an incident report, started an internal investigation, and implemented policies for localityName and stateOrProvinceName for the involved customer. SwissSign also stopped issuance of certificates and expanded remediation to additional customers, stating it had implemented the relevant policies for 35 identified customers and later identified 21 certificates from 7 customers with false localityName and/or stateOrProvinceName. SwissSign contacted affected customers and revoked the identified certificates, with a final report stating all 7 customers were contacted and all 21 identified certificates were revoked, and that SwissSign checked again for wrong or missing data. Mozilla indicated it would close the bug unless there were additional questions or issues to discuss, and the bug is marked RESOLVED with resolution FIXED.
- SwissSign issued a certificate containing a stateOrProvinceNameField value of "CH".
- SwissSign revoked the certificate after implementing localityName/stateOrProvinceName policies for the involved customer.
- SwissSign revoked all 21 identified certificates from 7 customers and completed its final checks.
- Fozzie representative — Reported that SwissSign issued a certificate with stateOrProvinceNameField value "CH" and noted this conflicted with SwissSign’s prior assurance in bug 1551364.
- SwissSign AG — Posted SwissSign’s initial incident report, describing internal investigation, implementation of localityName/stateOrProvinceName policies, and revocation of the certificate.
- Community commenter — Asked for clarification because the incident report lacked a binding remediation timeline.
- SwissSign AG — Provided a timeline update, committed to specific dates, stated issuance was stopped, and described remediation and revocation plans for identified customers.
- SwissSign AG — Updated the report with results, including identification of 21 certificates from 7 customers and a list of crt.sh IDs, and reiterated revocation by Friday 23 October 2020.
- SwissSign AG — Submitted a final report stating all 7 customers were contacted, all 21 identified certificates were revoked, and SwissSign rechecked for wrong or missing data.
- Mozilla representative — Questioned whether the incident report could be considered final without addressing the root cause and clarifying what policies were adopted/enforced.
- SwissSign AG — Explained the root cause as a query that only showed policies with content in the corresponding fields, and stated affected customers now have correct policies set so only configured localityName/stateOrProvinceName can be used.
- Mozilla representative — Stated the bug would be closed on 3-Feb-2021 unless additional questions or issues arose.