SwissSign: Invalid CT data in issued certs (SABRE.CT misconfiguration)
SwissSign reported an incident involving invalid Certificate Transparency (CT) data in certificates it issued, attributed to a SABRE.CT misconfiguration. The CA said one of its employees became aware of an external article mentioning SwissSign and informed the compliance team to investigate. SwissSign opened an internal compliance incident and operations investigated whether it had issued certificates with fewer than three correct Signed Certificate Timestamps (SCTs), confirming misissuance. The CA stated that misissuance stopped on March 16, 2023 at 12:28 UTC after Sectigo corrected the wrong software configuration from a private key of a test log back to the public key. SwissSign provided details for four SSL certificates issued during March 15–16 and said it would revoke the affected certificates by April 1, 2023 18:00 CEST at the latest, while also analyzing why SCT signature validation failed and defining and implementing improvement measures. A Mozilla participant indicated the bug would be closed as “Invalid,” and the bug is currently marked RESOLVED with resolution INVALID.
- SwissSign issued SSL certificates later identified as having invalid CT/SCT data.
- Misissuance stopped after Sectigo corrected the SABRE.CT configuration (test log private key back to public key).
- SwissSign employee notified compliance after noticing an external article mentioning SwissSign.
- SwissSign published its incident report and provided certificate details and remediation steps.
- Mozilla closed the bug as INVALID (as indicated in the thread).
- SwissSign AG — Described how SwissSign became aware of the issue, confirmed misissuance related to SCT signature validation, listed affected certificates, and stated revocation and remediation steps with target dates.
- Mm representative — Argued the certificates comply with RFC 6962 and relevant root store policies because no policy mandates specific CT logs, and suggested closing the bug as INVALID.
- Mozilla representative — Indicated he would close the bug as "Invalid" on Friday, 31-March-2023, unless other reasons applied.