KIR S.A.: DV certificates with locality name, organization name and stateOrProvinceName
Krajowa Izba Rozliczeniowa S.A. (KIR) issued DV certificates that incorrectly included organizationName, localityName, and stateOrProvinceName fields, violating compliance policies. The issue was identified shortly after issuance, leading to the revocation of the certificates. KIR acknowledged the mistake was due to a human error in applying the wrong policy OID and has since implemented measures to prevent recurrence, including improved naming conventions and a review process for new entries. Despite the prompt revocation, KIR initially did not classify the incident as reportable, which raised concerns among participants regarding their compliance practices.
- Two certificates issued with incorrect OID
- Certificates revoked after issue was identified
- Bug reported in Bugzilla
- Bug closed as fixed