← e-commerce monitoring GmbH cases
Bugzilla #1830536 Certificate Misissuance

e-commerce monitoring GmbH: certificate issued with two pre-certificates

RESOLVED FIXED e-commerce monitoring GmbH
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The case concerns an issuance incident for a leaf certificate where the CA’s internal control system showed that there were two pre-certificates associated with one leaf certificate. The CA stated this occurred because the first pre-cert issued did not have enough CT-log timestamp entries, leading to a follow-up pre-cert. The CA reported that its technical check systems (Cablint, x509lint, zlint) did not produce errors or warnings. The CA also stated that it was not possible for it to issue a leaf certificate with the same serial number, and that it revoked the unused pre-certificate identified during analysis. In response, the CA converted its software to a new CT log URL format and revised the relevant module, and it implemented programmatic measures to prevent pre-certificates with the same serial number from being issued. The CA later reported additional improvements, including more closely monitoring the list of usable CT log servers, and stated that it considered the underlying problem remediated with no further changes planned at the time. The bug was resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:22 UTC Revised: 2026-06-16 18:31 UTC Confidence: 0.74 8 comments
Chronology
  1. The CA’s internal control system detected two pre-certificates for one leaf certificate and identified the cause as insufficient CT-log timestamp entries on the first pre-cert.
  2. The CA responded to a related report and described remediation steps, including programmatic measures to prevent duplicate pre-certificates by serial number.
  3. The CA reported further improvements and stated the underlying problem was remediated with no further changes planned.
  4. Mozilla planned to close the bug unless additional questions or concerns were raised.
Thread Activity
  1. e-commerce monitoring GmbH — Opened the incident report describing issuance of one leaf certificate with two pre-certificates, the CT-log timestamp/URL-format cause, and remediation steps including revocation and software/module changes.
  2. Google representative — Asked for specific steps the CA took to detect future CT log operator changes in time and requested lessons learned from the incident.
  3. Zeger representative — Described an automated check of relevant CT log files (including log_list.json.auto.html) and stated a general lesson about not trusting external services not developed entirely by the CA.
  4. Mozilla representative — Asked whether the bug should be categorized as uncategorized or as an OV misissuance item.
  5. Mozilla representative — Requested a status update on the bug.
  6. e-commerce monitoring GmbH — Reported additional improvements (monitoring usable CT log servers and preventing same issuer/serial number situations) and stated no further changes were planned.
  7. Mozilla representative — Indicated the bug would be closed on 11-Oct-2023 unless additional questions or concerns were raised.
Participants
e-commerce monitoring GmbH Community commenter Google representative Zeger representative Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1815534 RESOLVED Ca Certificate Compliance Certificate Misissuance Revocation Issue Opened 2023-02-07 · Closed 2024-04-17 · 84% similar
e-commerce monitoring GmbH: SCT in precertificate
#1716123 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-06-12 · Closed 2024-05-25 · 77% similar
e-commerce monitoring GmbH: CN domain not in SAN
#1921597 RESOLVED Certificate Misissuance Opened 2024-09-28 · Closed 2025-02-19 · 76% similar
KIR: Intermediate CA - SZAFIR Trusted CA4 - Certificate Policies extension - non-compliance
#1745015 RESOLVED Certificate Misissuance Opened 2021-12-08 · Closed 2023-02-22 · 76% similar
eMudhra: emSign CA Invalid OrganizationalUnitName
#1883843 RESOLVED Certificate Misissuance Opened 2024-03-06 · Closed 2024-08-13 · 75% similar
Entrust: EV TLS Certificate cPSuri missing
#1921598 RESOLVED Certificate Misissuance Opened 2024-09-28 · Closed 2025-02-19 · 75% similar
KIR: Intermediate CA - SZAFIR Trusted CA3 - Certificate Policies extension - non-compliance
#1890898 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2024-04-11 · Closed 2024-07-28 · 74% similar
Entrust: Failure to revoke OV TLS - CPS typographical (text placement) error
#1853663 RESOLVED Certificate Misissuance Opened 2023-09-18 · Closed 2024-05-09 · 72% similar
Asseco DS / Certum: SMIME certificates with wrong organizationIdentifier

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action