← Krajowa Izba Rozliczeniowa S.A. (KIR) cases
Bugzilla #1705337
Certificate Problem Report
KIR S.A.: Invalid localityName + CRL Revoked but OCSP Unknown
RESOLVED
FIXED
Krajowa Izba Rozliczeniowa S.A. (KIR)
AI Summary
Krajowa Izba Rozliczeniowa S.A. (KIR) identified an issue with a certificate that contained a typo in the `localityName`, incorrectly stating 'Waraszawa' instead of 'Warszawa'. Although the certificate was revoked in the Certificate Revocation List (CRL), the Online Certificate Status Protocol (OCSP) returned an 'unknown' status initially. KIR took immediate action by revoking the certificate and has since implemented measures to ensure accurate locality and state information in future certificates. They are also reviewing all historically issued certificates for similar inaccuracies.
Chronology
- Certificate issued and immediately revoked.
- Issue reported and assigned to KIR.
- KIR confirmed OCSP status updated to revoked.
- KIR completed scan of historic issuance.
Participants
Michel Le Bihan
Piotr Grabowski
Ryan Sleevi
External References
Similar Local Cases
KIR S.A.: DV certificates with locality name, organization name and stateOrProvinceName
KIR S.A.: Invalid organizationName
KIR S.A.: CN domain not in SAN
KIR S.A.: Many certificates with OCSP Unknown
KIR S.A.: Certificates issued greater than stated in CPS
KIR S.A.: O > 64 characters
KIR: Failure to disclose intermediate certificate within 7 days in ccadb
KIR: Failure to disclose intermediate certificate within 7 days in ccadb