← Government of Turkey, Kamu Sertifikasyon Merkezi (Kamu SM) cases
Bugzilla #1847193
Certificate Problem Report
KAMU SM: commonName not in SAN
RESOLVED
FIXED
Government of Turkey, Kamu Sertifikasyon Merkezi (Kamu SM)
AI Summary
KAMU SM identified a misissuance where a certificate was issued without a commonName (CN) in the Subject Alternative Name (SAN) extension. The certificate was promptly revoked upon discovery. The CA has since implemented additional controls in their issuance checklist and is in the process of integrating pre-issuance linting into their certificate management infrastructure to prevent future occurrences. The incident has been resolved with all planned remediation activities completed.
Chronology
- Certificate issued without CN in SAN
- Certificate revoked
- Pre-issuance linting operational
Participants
Melis Şimşek
Daniel McCarney
Ben Wilson
External References
Similar Local Cases
Kamu SM: Insufficient Serial Number Entropy
DigiCert: 4 CRLs unavailable or not responding
DigiCert: Certificates issued inconsistent with S/MIME BR v1.0.1
Digicert: SMIME certificate with unvalidated information
Sectigo: Mojibake in certificate Subject fields
Sectigo: QWAC certificates issued with incorrect subject:organizationIdentifier attribute value
SwissSign: Invalid CT data in issued certs (SABRE.CT misconfiguration)
NETLOCK: CRL Error on CRL Watch of NETLOCK DVCA CRL