SwissSign: S/MIME LCP: CN with values other than email address
SwissSign AG reported a mis-issuance incident involving S/MIME certificates where the Common Name (CN) contained values other than email addresses. The issue was first identified on August 14, 2023, when a customer alerted SwissSign's support team. Following the discovery, SwissSign took immediate action to halt further mis-issuances and began revoking affected certificates. A total of 300 mis-issued certificates were identified, with revocation completed by August 20, 2023. SwissSign has implemented a series of remediation steps, including root cause analysis and the introduction of a new S/MIME linter to prevent future occurrences. The case is now resolved, with all necessary actions taken and improvements in place.
- Customer reported issue with mis-issued S/MIME certificates.
- All affected certificates were revoked.
- External S/MIME linter was implemented.
- SwissSign AG — Reported the mis-issuance incident and outlined the timeline of actions taken.
- SwissSign AG — Provided updates on remediation steps and confirmed revocation timeline.
- SwissSign AG — Confirmed that the patch to include the external S/MIME linter is now in production.
- Mozilla representative — Indicated that remediation of the issue is complete and planned to close the bug.