certSIGN: misissued an OV SSL certificate with no organizationName and localityName, instead of a DV SSL as requested by client
certSIGN reported a misissuance incident involving an OV SSL certificate that lacked the required organizationName and localityName, which was issued instead of a DV SSL certificate as requested by the client. The issue was first reported by an external party on October 31, 2020. Following the report, certSIGN conducted an internal investigation, revoked the misissued certificate, and acknowledged the error. To prevent future occurrences, certSIGN implemented updates to their pre-issuance checks and integrated new linting tools. The remediation steps were completed by November 2020, and the case has since been resolved.
- Issue reported by an external party
- Certificates revoked and remediation steps initiated
- Pre-issuance checks updated and new linting tools integrated
- certSIGN — Reported the misissuance incident and outlined the timeline of actions taken.
- Fozzie representative — Inquired about certSIGN's pre-issuance linting processes.
- certSIGN — Responded to inquiries about linting and confirmed plans to integrate zlint.
- certSIGN — Clarified a misunderstanding regarding the bug's status.
- certSIGN — Confirmed that remediation steps were completed.
- Mozilla representative — Indicated intention to close the bug.