← NAVER Cloud Trust Services cases
Bugzilla #1845269
Certificate Misissuance
NAVER Cloud Trust Services: commonName not in SAN
RESOLVED
FIXED
NAVER Cloud Trust Services
AI Summary
NAVER Cloud Trust Services identified a misissuance of an OV SSL certificate that did not include the commonName in the Subject Alternative Name (SAN) field. The issue was discovered during an internal audit on July 25, 2023, leading to the immediate revocation of the certificate. The root cause was traced to a lack of validation in the wildcard certificate issuance logic. NAVER has since implemented measures to prevent recurrence, including a patch to their internal system and additional pre-linting checks.
Chronology
- Certificate issued with commonName not in SAN
- Certificate revoked after internal audit
- Pre-linting based on Zlint added to CA Application
Participants
Han Yong, Park
Ben Wilson
External References
Similar Local Cases
NAVER Cloud Trust Services: OV certificate issued with OU field
NAVER Cloud Trust Services: DV certificate issued with no subject alternative name extension
NAVER Cloud Trust Services: DV Certificate issued with improperly validated
NAVER Cloud Trust Services: Certificate issued with incorrect OCSP URI in AIA
Izenpe: certificate issued to internal domain
NAVER Cloud Trust Services: Incorrect keyUsage for ECC certificate
SwissSign: Mis-Issuance of S/MIME certificates
SwissSign: Certificate with key length 16258