← e-commerce monitoring GmbH cases
Bugzilla #1716123
Certificate Problem Report
e-commerce monitoring GmbH: CN domain not in SAN
RESOLVED
FIXED
e-commerce monitoring GmbH
AI Summary
The case involves a compliance issue where a certificate issued by e-commerce monitoring GmbH contained a Common Name (CN) that was not included in the Subject Alternative Name (SAN) field. This incident raised concerns about the CA's pre-issuance checks and their ability to prevent such misissuance. Following the discovery, the CA halted certificate issuance and conducted a thorough investigation, ultimately implementing enhanced pre-issuance linting processes to prevent future occurrences. The incident was resolved with a commitment to transparency and improved compliance measures.
Chronology
- Initial report of the issue by the creator.
- GLOBALTRUST halted SSL certificate issuance.
- Final incident report created.
- Pre-issuance linting was realized.
Participants
Michel Le Bihan
Daniel Zens
Ryan Sleevi
Mathew Hodson
Andrew Ayer
Ben Wilson
External References
Similar Local Cases
e-commerce monitoring GmbH: Revoked test website not using revoked certificate
e-commerce monitoring GmbH: SCT in precertificate
KIR S.A.: CN domain not in SAN
e-commerce monitoring GmbH: CRLs with mismatched issuer
KIR S.A.: DV certificates with locality name, organization name and stateOrProvinceName
SwissSign: duplicate serial number
Google Trust Services: Invalid ASN.1 encoding of singleExtensions in OCSP responses
DigiCert: Invalid localityName