← e-commerce monitoring GmbH cases
Bugzilla #1815534 Certificate Problem Report

e-commerce monitoring GmbH: SCT in precertificate

RESOLVED FIXED e-commerce monitoring GmbH
AI Summary

The case involves e-commerce monitoring GmbH issuing multiple signed data structures with the same serial number, which included a pre-certificate poison extension and SCTs, violating RFC 6962. The incident was reported on February 7, 2023, and led to discussions about compliance with Mozilla's Root Store Policy. The CA acknowledged the issue and took steps to revoke the problematic certificates, which were eventually revoked on March 30, 2023. Improvements to their certificate issuance process were also implemented to prevent similar issues in the future.

Model: gpt-4o-mini Generated: 2026-06-13 21:21 UTC Confidence: 0.90
Chronology
  1. Bug filed regarding SCT issues in precertificate.
  2. Certificates with the problematic serial number were revoked.
  3. Incident report finalized and case closed.
Participants
Andrew Ayer Daniel Zens Hans Zeger Rob Ben Wilson Aaron Gable
External References
Similar Local Cases
#1716123 RESOLVED Certificate Problem Report Opened 2021-06-12 · Closed 2024-05-25 · 76% similar
e-commerce monitoring GmbH: CN domain not in SAN
#1716163 RESOLVED Certificate Problem Report Opened 2021-06-12 · Closed 2024-05-25 · 70% similar
e-commerce monitoring GmbH: Revoked test website not using revoked certificate
#1888371 RESOLVED Certificate Problem Report Opened 2024-03-28 · Closed 2024-07-09 · 67% similar
e-commerce monitoring GmbH: CRLs with mismatched issuer
#2023458 RESOLVED Certificate Problem Report Opened 2026-03-15 · Closed 2026-06-01 · 62% similar
D-Trust: TLS Precertificates Exceeding the Maximum Validity Period Allowed by the TLS Baseline Requirements
#1883711 RESOLVED Certificate Problem Report Opened 2024-03-05 · Closed 2024-07-09 · 62% similar
e-commerce monitoring gmbh: precertificate validity does not match leaf certificate
#1677737 RESOLVED Certificate Problem Report Opened 2020-11-17 · Closed 2023-02-22 · 58% similar
SwissSign: duplicate serial number
#1695938 RESOLVED Certificate Problem Report Opened 2021-03-02 · Closed 2024-06-30 · 57% similar
SECOM: FUJIFILM intermediate CA Certificate not listed in audit statement
#1906690 RESOLVED Certificate Problem Report Opened 2024-07-08 · Closed 2025-03-18 · 56% similar
Actalis: CRL distribution point with ldap scheme

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action