← SwissSign AG cases
Bugzilla #1851164 Ca Certificate Compliance Certificate Misissuance

SwissSign: S/MIME wrong key Usage

RESOLVED FIXED SwissSign AG
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

SwissSign reported a certificate misissuance involving S/MIME certificates. The issue was identified during an internal review while preparing to go live with sponsor-validated S/MIME profiles on its legacy CA system. SwissSign determined that it issued sponsor-validated S/MIME certificates with the key usage 'key agreement', which did not match its SwissSign S/MIME CPR. SwissSign stopped the misissuances within 30 minutes of detection and started its certificate mis-issuance process, informed the audit body, and began root cause analysis. In total, 106 certificates were mis-issued (102 valid and 4 revoked), with first issuance on 2023-08-28 19:07 and last issuance on 2023-08-30 23:31. SwissSign later confirmed that all affected certificates are revoked and described planned improvements, including better communication between product management, engineering, and QA teams and aligning automated tests with the update process. The bug was resolved as FIXED, and Mozilla indicated it intended to close the ticket if there were no open questions.

Model: gpt-5.4-nano Generated: 2026-06-13 20:49 UTC Revised: 2026-06-16 18:20 UTC Confidence: 0.90 5 comments
Chronology
  1. SwissSign began issuing S/MIME certificates using a new sponsor-validated profile as preparation for S/MIME BR on 1 September 2023.
  2. SwissSign detected a mismatch between its S/MIME CPR and the certificate KeyUsage during an internal review and stopped certificate issuance.
  3. SwissSign posted the Bugzilla incident report and started root cause analysis.
  4. SwissSign confirmed that all affected certificates are revoked.
  5. SwissSign reported deep-dive findings and process/test improvements and asked to close the bug if no questions remained.
Thread Activity
  1. SwissSign AG — Created the incident report describing the misissuance cause (key usage 'key agreement' not removed during legacy CA configuration), the timeline, and the aggregate count of mis-issued certificates.
  2. SwissSign AG — Confirmed that all affected certificates are revoked and stated deep dive and planned improvements were still under way.
  3. SwissSign AG — Reported investigation into automated testing to prevent recurrence and set the next update date.
  4. SwissSign AG — Stated improvements were introduced to requirement engineering communication and that automated tests would be aligned with the update process; asked to close if no open questions.
  5. Mozilla representative — Asked whether there were any questions and said Mozilla intended to close the bug on 22 Sept 2023 if none.
Participants
SwissSign AG Mozilla representative
Similar Local Cases
#1677737 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-11-17 · Closed 2023-02-22 · 100% similar
SwissSign: duplicate serial number
#1691704 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-02-09 · Closed 2023-02-22 · 100% similar
SwissSign: Certificate with key length 4098 bit
#1734131 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-10-05 · Closed 2023-02-22 · 100% similar
SwissSign: wrong address in EV certificate
#1866091 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-11-22 · Closed 2023-12-11 · 100% similar
SwissSign: EV JurisdictionStateOrProvinceName - one certificate not selected for revocation
#1670894 RESOLVED Certificate Misissuance Opened 2020-10-13 · Closed 2023-02-22 · 99% similar
SwissSign: Invalid stateOrProvinceName field
#1825232 RESOLVED Certificate Misissuance Self Reported Incident Opened 2023-03-29 · Closed 2023-03-31 · 97% similar
SwissSign: Invalid CT data in issued certs (SABRE.CT misconfiguration)
#1404403 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-09-29 · Closed 2023-02-22 · 90% similar
SwissSign: Two certs issued with same issuer and serial number
#1876771 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-01-26 · Closed 2024-02-08 · 90% similar
SwissSign: modified fields were not saved into certificates and resulted in miss-issuance

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action