← e-tugra cases
Bugzilla #1801345 Self Reported Incident Security Incident

E-Tugra incident report on internet-accessible internal application and potential certificate-management impact

RESOLVED FIXED e-tugra
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

E-Tugra opened this bug to disclose a security incident involving an internal application that was mistakenly made internet-accessible. The company said it first learned of the issue from an email by Ian Carroll on 2022-11-13, fixed the affected sites immediately, and began scanning and reviewing systems and access controls. In the thread, E-Tugra stated that the affected application was for reporting and that its CA systems were physically and logically separated, while participants repeatedly asked whether the exposed system could have affected certificate issuance or customer account access. E-Tugra later said the application did not participate in certificate issuance, that SSL.com handled domain validation for managed SubCAs during the transition period, and that no evidence showed malicious exploitation of the vulnerability. The case remained focused on incident response, penetration testing, remediation, and clarifying the relationship between the exposed application, customer portal functions, and the publicly trusted CA hierarchies. The bug was ultimately resolved as FIXED after E-Tugra posted an updated incident report and a penetration testing executive summary.

Model: gpt-5.4-mini Generated: 2026-06-13 21:26 UTC Revised: 2026-06-16 18:40 UTC Confidence: 0.93 54 comments
Chronology
  1. E-Tugra learned of the internet-accessible internal application from Ian Carroll and fixed the affected sites the same day.
  2. E-Tugra published an incident report describing the security issue and response.
  3. E-Tugra said the expanded penetration testing exercise was completed.
  4. E-Tugra posted an updated incident report.
  5. E-Tugra posted an executive summary of the penetration testing and verification report.
Thread Activity
  1. E-Tugra — E-Tugra filed the incident report, said it learned of the issue from Ian Carroll, and described immediate fixes and follow-up scanning.
  2. Google representative — Chris Clements asked for a more detailed timeline, separation details, and evidence about the scope and impact of the incident.
  3. E-Tugra — E-Tugra said its CA and non-CA systems were physically and logically separated and that the incident involved an internal non-SSL application.
  4. E-Tugra — E-Tugra said it ran monthly vulnerability scans, annual penetration tests, and a February 2022 risk assessment, and that upcoming testing would cover CA and non-CA systems.
  5. E-Tugra — E-Tugra said the reporting system received CA log information through secure tunneling and that the application did not directly participate in certificate issuance.
  6. E-Tugra — E-Tugra said the customer portal allowed re-issuing already validated DV certificates, but the accessed application did not affect that process.
  7. E-Tugra — E-Tugra said it found no evidence of malicious exploitation and had checked logs and issued certificates for impact.
  8. E-Tugra — E-Tugra said remediation measures were in place and that penetration testing was the only remaining action item.
  9. E-Tugra — E-Tugra said SSL.com managed SubCAs during the transition period and that the exposed application only stored logs for reporting purposes.
  10. E-Tugra — E-Tugra confirmed multiple SSL.com-managed SubCAs, said SSL.com handled domain validation, and said it would present evidence to LSTI auditors.
  11. E-Tugra — E-Tugra attached an updated incident report and said the detailed penetration testing reports would follow.
  12. E-Tugra — E-Tugra attached an executive summary of the penetration testing and listed several low-level findings.
Participants
E-Tugra Google representative Mozilla representative Ian representative Community commenter SSL.com Cagir representative E representative
Similar Local Cases
#1542302 RESOLVED Self Reported Incident Opened 2019-04-05 · Closed 2023-02-22 · 88% similar
E-Tugra: Insufficient serial number entropy
#1687139 RESOLVED Self Reported Incident Opened 2021-01-16 · Closed 2023-02-22 · 86% similar
E-Tugra: commonName not in SAN
#1904041 RESOLVED Ca Documents Self Reported Incident Opened 2024-06-21 · Closed 2025-07-01 · 85% similar
NETLOCK: Intermediate CA Certificate not disclosed to CCADB
#1815355 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2023-02-07 · Closed 2023-08-16 · 81% similar
Asseco DS / Certum: Cross-Signed non-EV-audited root with an EV-enabled root
#1582601 RESOLVED Self Reported Incident Certificate Misissuance Opened 2019-09-20 · Closed 2023-02-22 · 78% similar
E-Tugra: Invalid DER results in failure to comply with RFC 5280 - Violating string length limit
#1689589 RESOLVED Self Reported Incident Security Incident Opened 2021-01-29 · Closed 2023-02-22 · 76% similar
Telia: Disallowed curve (P-521) in leaf certificate
#1575530 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-08-21 · Closed 2023-02-22 · 76% similar
Camerfirma: Govern d'Andorra audits
#1879602 RESOLVED Security Incident Self Reported Incident Opened 2024-02-09 · Closed 2024-07-19 · 75% similar
Entrust: OCSP response signed with SHA-1

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action