← Microsec Ltd. cases
Bugzilla #1728384 Certificate Misissuance Incident

Microsec: Misissuance of one OV certificate with Key Usage KeyEncipherment

RESOLVED FIXED Microsec Ltd.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns Microsec misissuing one OV TLS certificate with an incorrect Key Usage setting (KeyEncipherment). Microsec stated it first became aware of the problem via an incident report email received on 2021-08-31 9:36 AM. Microsec investigated the cause, including a configuration problem that allowed an ECC end-entity key to be issued using an RSA certificate profile, and it reported that the manual post-issuance quality control check did not recognize the fault. Microsec contacted the site owner and planned revocation, and it revoked the incorrect certificate on 2021-08-31 10:12 UTC. Microsec also reported that it did not need to suspend certificate issuance because its quick investigation found current policy documents and certificate profiles were OK. In later status reports, Microsec described training for Registration Officers and additional controls (including profile configuration checks and automated CABLINT/ZLINT checks), and it stated no further action was planned. The bug was resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:13 UTC Revised: 2026-06-16 19:14 UTC Confidence: 0.86 4 comments
Chronology
  1. Microsec revoked the incorrectly issued OV certificate after investigating an incorrect Key Usage setting.
Thread Activity
  1. Microsec representative — Microsec reported the incident timeline, described the configuration/profile cause, and stated it revoked the incorrect certificate after contacting the site owner.
  2. Microsec representative — Microsec provided a status report including Registration Officer training and additional preventive controls, and stated no further action was planned.
  3. Microsec representative — Microsec reported a quarterly self-audit and stated it found no certificate misissuance in the sampled period.
  4. Mozilla representative — Mozilla stated it would close the bug the next day unless issues were raised.
Participants
Microsec representative Mozilla representative
External References
Similar Local Cases
#1676352 RESOLVED Certificate Misissuance Incident Opened 2020-11-10 · Closed 2023-02-22 · 100% similar
Microsec: Certificate validity period greater than 398 days
#1886257 RESOLVED Certificate Misissuance Opened 2024-03-19 · Closed 2024-08-28 · 97% similar
Microsec: Misissuance an EV TLS certificate without CPSuri
#1512270 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2018-12-05 · Closed 2023-02-22 · 81% similar
Microsec: Validity period greater than 825 days
#1743935 RESOLVED Certificate Misissuance Incident Opened 2021-12-02 · Closed 2023-02-22 · 80% similar
Amazon Trust Services: Misissuance of Subordinate Per CPS
#1649947 RESOLVED Certificate Misissuance Opened 2020-07-02 · Closed 2023-02-22 · 78% similar
Microsec: Incorrect OCSP Delegated Responder Certificate
#1844514 RESOLVED Revocation Issue Incident Opened 2023-07-20 · Closed 2024-03-13 · 77% similar
MICROSEC: Incident report - No OCSP status response for 2 Precertificates
#1744722 RESOLVED Certificate Misissuance Opened 2021-12-07 · Closed 2023-02-22 · 71% similar
FNMT: Invalid localityName
#1830536 RESOLVED Certificate Misissuance Opened 2023-04-28 · Closed 2024-05-11 · 71% similar
e-commerce monitoring gmbh: certificate issued with two pre-certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action