← SwissSign AG cases
Bugzilla #1825232 Certificate Misissuance Self Reported Incident

SwissSign: Invalid CT data in issued certs (SABRE.CT misconfiguration)

RESOLVED INVALID SwissSign AG
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

SwissSign reported an incident involving invalid Certificate Transparency (CT) data in certificates it issued, attributed to a SABRE.CT misconfiguration. The CA said one of its employees became aware of an external article mentioning SwissSign and informed the compliance team to investigate. SwissSign opened an internal compliance incident and operations investigated whether it had issued certificates with fewer than three correct Signed Certificate Timestamps (SCTs), confirming misissuance. The CA stated that misissuance stopped on March 16, 2023 at 12:28 UTC after Sectigo corrected the wrong software configuration from a private key of a test log back to the public key. SwissSign provided details for four SSL certificates issued during March 15–16 and said it would revoke the affected certificates by April 1, 2023 18:00 CEST at the latest, while also analyzing why SCT signature validation failed and defining and implementing improvement measures. A Mozilla participant indicated the bug would be closed as “Invalid,” and the bug is currently marked RESOLVED with resolution INVALID.

Model: gpt-5.4-nano Generated: 2026-06-13 20:49 UTC Revised: 2026-06-16 18:19 UTC Confidence: 0.86 3 comments
Chronology
  1. SwissSign issued SSL certificates later identified as having invalid CT/SCT data.
  2. Misissuance stopped after Sectigo corrected the SABRE.CT configuration (test log private key back to public key).
  3. SwissSign employee notified compliance after noticing an external article mentioning SwissSign.
  4. SwissSign published its incident report and provided certificate details and remediation steps.
  5. Mozilla closed the bug as INVALID (as indicated in the thread).
Thread Activity
  1. SwissSign AG — Described how SwissSign became aware of the issue, confirmed misissuance related to SCT signature validation, listed affected certificates, and stated revocation and remediation steps with target dates.
  2. Mm representative — Argued the certificates comply with RFC 6962 and relevant root store policies because no policy mandates specific CT logs, and suggested closing the bug as INVALID.
  3. Mozilla representative — Indicated he would close the bug as "Invalid" on Friday, 31-March-2023, unless other reasons applied.
Participants
SwissSign AG Mm representative Mozilla representative
Similar Local Cases
#1851164 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-09-01 · Closed 2023-09-22 · 97% similar
SwissSign: S/MIME wrong key Usage
#1866091 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-11-22 · Closed 2023-12-11 · 96% similar
SwissSign: EV JurisdictionStateOrProvinceName - one certificate not selected for revocation
#1677737 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-11-17 · Closed 2023-02-22 · 94% similar
SwissSign: duplicate serial number
#1459557 RESOLVED Self Reported Incident Certificate Misissuance Opened 2018-05-07 · Closed 2023-02-22 · 91% similar
SwissSign: Certificate issue with Signature
#1734131 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-10-05 · Closed 2023-02-22 · 91% similar
SwissSign: wrong address in EV certificate
#1670894 RESOLVED Certificate Misissuance Opened 2020-10-13 · Closed 2023-02-22 · 89% similar
SwissSign: Invalid stateOrProvinceName field
#1691704 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-02-09 · Closed 2023-02-22 · 89% similar
SwissSign: Certificate with key length 4098 bit
#1876771 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-01-26 · Closed 2024-02-08 · 89% similar
SwissSign: modified fields were not saved into certificates and resulted in miss-issuance

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action