← certSIGN cases
Bugzilla #1763173 Certificate Misissuance

certSIGN: Incorrect data in stateOrProvinceName

RESOLVED FIXED certSIGN
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case reports that certSIGN operators identified an issuance problem affecting an OV SSL pre-certificate where the stateOrProvinceName value was incorrect. The issue was triggered when, after an internal request for an OV SSL certificate, the RA operators created a pre-certificate and the CA software update caused the automatic verification (linter warnings) to be skipped due to a technical issue, allowing the pre-certificate to be issued. certSIGN stated that the problem was discovered during a second verification post-issuance, after which the pre-certificate was revoked. certSIGN reported that the root cause was a bug in the CA software update and that it was fixed by rolling back to the previous configuration. The CA said it would treat all warnings as exceptions and keep the update in production until 31 May 2022 while testing additional test cases. certSIGN also stated it would continue monitoring production certificate issuance and later reported that the planned update was deployed in production. The bug was resolved as FIXED, and Mozilla indicated it would be closed on or about 3 June 2022.

Model: gpt-5.4-nano Generated: 2026-06-13 21:26 UTC Revised: 2026-06-16 18:22 UTC Confidence: 0.90 7 comments
Chronology
  1. An OV SSL pre-certificate was issued with an incorrect stateOrProvinceName due to a CA software update issue affecting linter warnings.
  2. The affected pre-certificate was revoked after the error was detected in post-issuance verification.
  3. certSIGN deployed the planned update in the production environment.
Thread Activity
  1. certSIGN — Reported that an OV SSL pre-certificate was issued after linter warnings were skipped due to a CA software update bug, and that the pre-certificate was revoked after the incorrect stateOrProvinceName was found.
  2. Community commenter — Asked for more detail on how the system allowed the invalid stateOrProvinceName and how the operator decided to override the warning.
  3. certSIGN — Explained that the stateOrProvinceName was filled wrong on the CSR request, that the update prevented warnings from reaching the operator, and that the operator assumed linting succeeded; described the linter-based validation process and the identified weakness.
  4. certSIGN — Stated that certSIGN would continue monitoring production certificate issuance and would post another status update on April 29, 2022.
  5. certSIGN — Stated that certSIGN would continue monitoring and would post another status update until May 31, 2022.
  6. certSIGN — Reported that the planned update had been deployed in the production environment.
  7. Mozilla representative — Indicated Mozilla would close the bug on or about Friday, 3 June 2022.
Participants
certSIGN Community commenter Mozilla representative
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#1762707 RESOLVED Certificate Misissuance Opened 2022-04-02 · Closed 2023-02-22 · 89% similar
certSIGN: Subscriber precertificate without Certificate Policies
#1674886 RESOLVED Certificate Misissuance Opened 2020-11-02 · Closed 2023-02-22 · 79% similar
certSIGN: misissued an OV SSL certificate with no organizationName and localityName, instead of a DV SSL as requested by client
#1398243 RESOLVED Certificate Misissuance Opened 2017-09-08 · Closed 2023-02-22 · 70% similar
certSIGN: Non-BR-Compliant OCSP Responders
#1582601 RESOLVED Self Reported Incident Certificate Misissuance Opened 2019-09-20 · Closed 2023-02-22 · 68% similar
E-Tugra: Invalid DER results in failure to comply with RFC 5280 - Violating string length limit
#1672423 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2020-10-21 · Closed 2023-02-22 · 63% similar
Camerfirma: certificate for unregistered domain cuatis.net
#1841534 RESOLVED Self Reported Incident Certificate Misissuance Opened 2023-07-03 · Closed 2023-08-30 · 63% similar
Apple: TLS certificates issued outside the TTL of the CAA record
#1746945 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-12-20 · Closed 2023-02-22 · 63% similar
Amazon Trust Services: Missing CAA Check For Test Website Certificates
#1802916 RESOLVED Ca Certificate Compliance Certificate Misissuance Remediation Tracking Opened 2022-11-28 · Closed 2023-04-24 · 62% similar
Entrust: EV TLS Certificate incorrect jurisdiction

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action