← NAVER Cloud Trust Services cases
Bugzilla #1845269 Certificate Misissuance Incident

NAVER Cloud Trust Services: commonName not in SAN (internal audit misissuance)

RESOLVED FIXED NAVER Cloud Trust Services
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

NAVER Cloud Trust Services reported a misissuance discovered during its internal audit for the second quarter. The CA stated it became aware that an OV SSL certificate issued via its internal certificate issuance system (NDCM) had a commonName that was not included in the Subject Alternative Name (SAN). The CA said it immediately revoked the affected certificate on 2023-07-25 10:43 and suspended wildcard certificate issuance through NDCM. In its incident report, the CA attributed the issue to missing validation in the wildcard certificate issuance logic (CN of the CSR not being validated against the applicant-entered domain that later populates SAN), and noted that the x509 lint applied to the CA failed to catch the “commonName not in SAN” condition. The CA reported applying an NDCM hotfix to disallow mismatched CN/domain requests and completing additional pre-linting based on Zlint in the CA application (completed 2023-08-21 07:30). Mozilla asked whether remediation was complete, and the CA confirmed the root cause was addressed and measures to prevent recurrence were fully implemented; the bug was resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 20:55 UTC Revised: 2026-06-16 18:36 UTC Confidence: 0.90 6 comments
Chronology
  1. NAVER Cloud Trust Services issued an OV SSL certificate where the commonName was not included in the SAN.
  2. NAVER Cloud Trust Services revoked the affected certificate and suspended wildcard certificate issuance through NDCM after discovering the issue in an internal audit.
  3. NAVER Cloud Trust Services completed adding pre-linting based on Zlint to its CA application.
Thread Activity
  1. Navercorp representative — Reported that an internal audit found an OV SSL certificate with commonName not in SAN, and stated the certificate was revoked and investigations were started.
  2. Navercorp representative — Posted a full incident report with a timeline, root cause, and remediation steps including an NDCM hotfix and planned CA-side pre-linting.
  3. Navercorp representative — Confirmed Zlint-based pre-linting was completed in the CA application on 2023-08-21 07:30.
  4. Mozilla representative — Asked whether the issue was fully remediated and whether measures were in place to prevent recurrence.
  5. Navercorp representative — Confirmed the root cause was addressed and recurrence prevention measures were fully implemented.
  6. Mozilla representative — Indicated intent to close the bug on 2023-09-29 unless further questions arose.
Participants
Navercorp representative Mozilla representative
Similar Local Cases
#1866448 RESOLVED Certificate Misissuance Incident Opened 2023-11-24 · Closed 2024-02-14 · 100% similar
NAVER Cloud Trust Services: DV Certificate issued with improperly validated
#1908128 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-07-16 · Closed 2024-08-28 · 91% similar
NAVER Cloud Trust Services: Certificate issued with incorrect OCSP URI in AIA
#1908130 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-07-16 · Closed 2024-08-28 · 91% similar
NAVER Cloud Trust Services: Incorrect keyUsage for ECC certificate
#1651026 RESOLVED Certificate Misissuance Incident Remediation Tracking Opened 2020-07-07 · Closed 2023-02-22 · 82% similar
Izenpe: certificate issued to internal domain
#1785865 RESOLVED Certificate Misissuance Opened 2022-08-18 · Closed 2024-05-09 · 80% similar
NAVER Cloud Trust Services: DV certificate issued with no subject alternative name extension
#1932973 RESOLVED Certificate Misissuance Incident Opened 2024-11-22 · Closed 2025-04-07 · 77% similar
SSL.com: CAA Empty set handling results in Wildcard issuance
#1717357 RESOLVED Certificate Misissuance Incident Opened 2021-06-20 · Closed 2023-02-22 · 77% similar
Actalis: Issuance of intermediates after 2020-08-20 that do not comply with Mozilla Policy and the Baseline Requirements
#1963663 RESOLVED Incident Certificate Misissuance Opened 2025-04-30 · Closed 2025-06-12 · 76% similar
Certigna: Multiple Reserved Certificate Policy Identifiers in CA certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action