← e-commerce monitoring GmbH cases
Bugzilla #1830536
Certificate Misissuance
e-commerce monitoring gmbh: certificate issued with two pre-certificates
RESOLVED
FIXED
e-commerce monitoring GmbH
AI Summary
The case involves e-commerce monitoring GmbH, which issued a leaf certificate associated with two pre-certificates due to insufficient ct-log timestamp entries. This incident was identified on February 7, 2023, and was linked to a prior bug report. The CA took immediate corrective actions, including implementing automated checks for ct-log servers to prevent future occurrences. The issue was resolved with no further changes planned, as the underlying problem was deemed remediated.
Chronology
- Internal control system identified two pre-certificates for one leaf certificate.
- CA responded to the issue, explaining the cause and implementing programmatic measures.
- Inquiry from Ryan Dickson regarding steps taken to prevent future issues.
- CA implemented automated checks for ct-log servers.
- CA reported improvements and stated the underlying problem was remediated.
- Final status update before closure of the case.
Participants
Daniel Zens
Ryan Dickson
Hans Zeger
Ben Wilson
External References
Similar Local Cases
Certigna: TLS certificates with Basic constraint non-critical
Entrust: EV TLS Certificate cPSuri missing
Digicert: Failure to include CPS URI in 1 certificate
eMudhra: emSign CA ECC Test Certificate Misissuance
SwissSign: S/MIME LCP: CN with values other than email address
Sectigo: Incorrect inclusion of DBA name
TWCA: CA certificate without EKU
SwissSign: Certificate with key length 16258