← certSIGN cases
Bugzilla #1674886
Certificate Misissuance
certSIGN: misissued an OV SSL certificate with no organizationName and localityName, instead of a DV SSL as requested by client
RESOLVED
FIXED
certSIGN
AI Summary
certSIGN misissued an OV SSL certificate instead of a DV SSL certificate as requested by a client due to a human error during the issuance process. The error occurred when an RA operator selected the wrong pre-certificate profile, which went unnoticed by subsequent checks. Upon realization, certSIGN promptly revoked the misissued certificates and initiated an internal investigation. They have since implemented additional technical controls to prevent similar incidents in the future.
Chronology
- Issue reported by client via email
- Certificates revoked and internal investigation started
- Pre-issuance checks updated to include zlint
Participants
Gabriel PETCU
george@fozzie.dev
bogdan.patrascu@certsign.ro
ryan.sleevi@gmail.com
bwilson@mozilla.com
External References
Similar Local Cases
certSIGN: Subscriber precertificate without Certificate Policies
Sectigo: Subject field with unvalidated information included in certificates
SSL.com: Wildcard DV certificate issued with a non-validated domain name
GDCA: Incorrect Value in organizationName Field
SSL.com: Incorrect Domain Validation for 1 TLS certificate with FQDN having "www." string within domain labels
Telekom Security: Certificate with invalid FQDN
GlobalSign: Misissuance of QWAC Certificates
Dhimyotis / Certigna: Certificates issued with validity periods greater than 398-days