← eMudhra Technologies Limited cases
Bugzilla #1763700 Certificate Misissuance

eMudhra: emSign CA invalid AIA extension value (84 misissued SSL certificates)

RESOLVED FIXED eMudhra Technologies Limited
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case reports that eMudhra’s emSign CA misissued 84 SSL certificates with invalid Authority Information Access (AIA) extension values. The CA said it first became aware of the problem on 06-Apr-2022 after receiving an email reporting a certificate with an invalid AIA value, and it confirmed the certificates were misissued on 06-Apr-2022. eMudhra initiated system configuration inspection and changes to mitigate the issue, completed verification that new issuances were proper, and scanned to identify affected certificates. The CA notified subscribers on 07-Apr-2022, completed revocation of the affected certificates on 07-Apr-2022, and issued replacement certificates that were verified for successful mitigation. In the thread, Mozilla reviewers asked for clearer root cause analysis and the CA provided additional details, stating the cause involved human error due to AIA configuration field misconfiguration and lack of UI intuitiveness. eMudhra also described remediation steps including changes to the admin application UI (with an expected patch date of 30-Apr-2022) and stated that the software update was deployed successfully and remediation was completed. The bug was resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:22 UTC Revised: 2026-06-16 18:31 UTC Confidence: 0.90 8 comments
Chronology
  1. The first of the affected SSL certificates was issued with invalid AIA values.
  2. eMudhra received a report of an invalid AIA value and began investigating and mitigating the misissuance.
  3. eMudhra notified subscribers, completed revocation of affected certificates, and issued verified replacement certificates.
  4. eMudhra expected a patch to update descriptive UI field names for AIA configuration.
  5. eMudhra reported the software update was deployed and remediation actions were completed.
Thread Activity
  1. Emudhra representative — Filed the incident report stating 84 SSL certificates were wrongly issued with invalid AIA values, described investigation/mitigation steps, and reported revocation and replacement issuance.
  2. Community commenter — Asked for clearer, more concrete root cause analysis and a redo of the incident report answers with specific details and timeline.
  3. Emudhra representative — Said an update would be posted within the next few days (before 14-Apr-2022).
  4. Community commenter — Questioned why the certificate list did not use the recommended crt.sh URL form and asked whether eMudhra follows the dev-security-policy mailing list.
  5. Emudhra representative — Provided crt.sh URLs for the listed certificates as an update to the thread.
  6. Emudhra representative — Provided an updated root cause analysis and remediation plan, including UI intuitiveness issues and a change request to update descriptive field names, with an expected patch by 30-Apr-2022.
  7. Emudhra representative — Reported no new updates and said the software update was scheduled for next week, with a closure update afterward.
  8. Emudhra representative — Reported the software update was deployed successfully, confirmed remediation was completed, and requested the bug be marked Resolved.
Participants
Emudhra representative Community commenter
Similar Local Cases
#1745015 RESOLVED Certificate Misissuance Opened 2021-12-08 · Closed 2023-02-22 · 95% similar
eMudhra: emSign CA Invalid OrganizationalUnitName
#1665688 RESOLVED Certificate Misissuance Opened 2020-09-17 · Closed 2023-02-22 · 82% similar
eMudhra: emSign CA ECC Test Certificate Misissuance
#1667518 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-09-26 · Closed 2023-02-22 · 78% similar
QuoVadis: Incorrect keyUsage for ECC certificate
#1401211 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-09-19 · Closed 2023-02-22 · 70% similar
NetLock: Non-BR-Compliant Certificate Issuance -- * in not the leftmost position in dnsName
#1463975 RESOLVED Certificate Misissuance Delayed Revocation Opened 2018-05-24 · Closed 2023-02-22 · 70% similar
GRCA: Misissued certificates: Invalid commonName, commonName not in SAN
#1353827 RESOLVED Certificate Misissuance Opened 2017-04-05 · Closed 2023-02-22 · 70% similar
DigiCert: DigiCert issued cert with CN too long
#1390988 RESOLVED Ca Certificate Compliance Incident Externally Reported Incident Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 70% similar
Consorci AOC: Non-BR-Compliant Certificate Issuance
#1390977 RESOLVED Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 70% similar
Camerfirma: Non-BR-Compliant Certificate Issuance

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action