Microsec: Certificate validity period greater than 398 days
Microsec Ltd. reported the misissuance of two CISCO VPN server authentication certificates with a validity period exceeding 398 days. The CA discovered the issue during an internal quality check and promptly revoked both certificates within 24 hours of issuance. The incident was documented, and Microsec identified a flaw in their certificate profile management system as the root cause. They have since implemented corrective measures, including a review of all certificate profiles and improvements to their management system to prevent future occurrences. The case has been resolved with the status marked as 'FIXED'.
- Revocation of two misissued CISCO VPN server authentication certificates.
- Lebihan representative — Reported two certificates issued with a validity of 2 years.
- Mozilla representative — Documented the incident and requested a timeline of actions taken.
- Microsec representative — Provided a status report detailing actions taken to resolve the misissuance.
- Microsec representative — Confirmed that the affected certificate profile was suspended and improvements were made.
- Microsec representative — Updated on the ongoing investigation and improvements to the certificate management system.
- Mozilla representative — Indicated intention to close the bug as resolved.