← SwissSign AG cases
Bugzilla #1691704 Ca Certificate Compliance Certificate Misissuance

SwissSign: Certificate with key length 4098 bit

RESOLVED FIXED SwissSign AG
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

SwissSign reported that it was informed by a third party that it had issued a pre-certificate/certificate with a 4098-bit key length on 2019-08-05, which violates the Mozilla root store policy v.2.6.1 effective 2018-07-01. SwissSign stated that the SC31 “Browser alignment” became effective with BR 1.7.1 on 2020-08-20, and that the baseline regulation was not violated at that later time. SwissSign said it confirmed the misissuance after first and second analysis, and that only two certificates (a Pre and a Leaf) were affected. SwissSign stated it had stopped the issue from recurring by implementing and testing technical controls in January 2020, and it explained that invalid key lengths are denied in the request handler before linting or issuing the pre-certificate. The CA reported revocation of the certificate until 2021-02-13 (within 5 days since acknowledging the misissuance) and later stated the certificates were revoked as of 2021-02-12 13:25:32 UTC. Mozilla indicated it would schedule to close the case on 2021-03-10, and the bug is resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 20:50 UTC Revised: 2026-06-16 18:18 UTC Confidence: 0.86 7 comments
Chronology
  1. SwissSign issued a pre-certificate/certificate with a 4098-bit key length.
  2. SwissSign received a third-party report about the 4098-bit key length misissuance.
  3. SwissSign acknowledged the report and confirmed the misissuance after analysis.
  4. SwissSign revoked the affected certificates.
  5. Mozilla scheduled closure of the case.
Thread Activity
  1. SwissSign AG — SwissSign reported that it was informed by a third party of a 4098-bit key length misissuance on 2019-08-05, confirmed only two certificates were affected, and stated revocation actions and remediation controls.
  2. Mozilla representative — Mozilla asked whether SwissSign scans its database for existing certificates with the issue when adding controls, and if not, why not.
  3. SwissSign AG — SwissSign replied that it usually scans but had no explanation for why it did not do so after implementing the technical control.
  4. SwissSign AG — SwissSign stated the certificates were revoked as of 2021-02-12 13:25:32 UTC.
  5. Mozilla representative — Mozilla asked how the January 2020 technical control prevents future problems and what it covers.
  6. SwissSign AG — SwissSign explained that invalid key lengths are denied in the request handler before linting or issuing the pre-certificate, applying to all certificates of its public roots.
  7. Mozilla representative — Mozilla said it would schedule to close the case on 2021-03-10.
Participants
SwissSign AG Mozilla representative
Similar Local Cases
#1677737 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-11-17 · Closed 2023-02-22 · 100% similar
SwissSign: duplicate serial number
#1734131 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-10-05 · Closed 2023-02-22 · 100% similar
SwissSign: wrong address in EV certificate
#1851164 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-09-01 · Closed 2023-09-22 · 100% similar
SwissSign: S/MIME wrong key Usage
#1866091 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-11-22 · Closed 2023-12-11 · 99% similar
SwissSign: EV JurisdictionStateOrProvinceName - one certificate not selected for revocation
#1670894 RESOLVED Certificate Misissuance Opened 2020-10-13 · Closed 2023-02-22 · 98% similar
SwissSign: Invalid stateOrProvinceName field
#1404403 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-09-29 · Closed 2023-02-22 · 90% similar
SwissSign: Two certs issued with same issuer and serial number
#1825232 RESOLVED Certificate Misissuance Self Reported Incident Opened 2023-03-29 · Closed 2023-03-31 · 89% similar
SwissSign: Invalid CT data in issued certs (SABRE.CT misconfiguration)
#1876771 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-01-26 · Closed 2024-02-08 · 89% similar
SwissSign: modified fields were not saved into certificates and resulted in miss-issuance

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action