← Telia Company cases
Bugzilla #1856591 Certificate Misissuance

Telia: S/MIME certificates issued in violation of S/MIME BR v1.0.1

RESOLVED FIXED Telia Company
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Telia reported that it issued three S/MIME certificates in violation of S/MIME Baseline Requirements (S/MIME BR) v1.0.1. Telia said it became aware of the issue during its monthly compliance review on 2023-10-02 for S/MIME certificates issued in September 2023, and identified that the certificates were issued on 2023-09-01 by a technically constrained CA to Telefonaktiebolaget LM Ericsson AB personnel. Telia stated the certificates were missing a required Policy OID for “S/MIME BR Sponsor validated Legacy (2.23.140.1.5.3.1)” and were missing the required organizationIdentifier in the Subject (attribute 2.5.4.97), violating S/MIME BR v1.0.1 sections 7.1.6.1 and 7.1.4.2.2(d). Telia opened an incident report in Mozilla Bugzilla and performed an immediate review and a full compliance check, stating that no other problematic certificates were found. Telia notified affected certificate holders and reported that the problematic certificates were revoked, with revocation timestamps later corrected in a follow-up comment. Telia later reported that remedial actions were completed, including deploying daily linting with digicert/pkilint to verify S/MIME certificate compliance, and requested closure; Mozilla indicated it would close the incident on 2024-01-26. The bug is resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 20:51 UTC Revised: 2026-06-16 18:17 UTC Confidence: 0.90 8 comments
Chronology
  1. Three S/MIME certificates were issued via API calls by a technically constrained CA.
  2. Telia performed a monthly compliance review and identified three non-compliant S/MIME certificates from September 2023.
  3. Telia opened an incident report in Mozilla Bugzilla and completed an immediate review and full compliance check.
  4. Telia reported revocation of the problematic certificates and later corrected revocation timestamps for two certificates.
  5. Telia reported deploying daily linting with digicert/pkilint for S/MIME certificate compliance verification.
  6. Telia requested closure after planned tasks were completed; Mozilla scheduled closure for 2024-01-26.
Thread Activity
  1. Teliacompany representative — Opened the initial incident report, describing the non-compliance findings and stating affected certificates would be revoked by 2023-10-04 17:00 EET.
  2. Teliacompany representative — Updated that the problematic certificates had been revoked and listed revocation times (as initially reported).
  3. Teliacompany representative — Corrected revocation timestamps for two certificates due to a copy/paste error.
  4. Teliacompany representative — Provided the full incident report and continued monitoring of action items.
  5. Teliacompany representative — Reported that Tasks 2 and 3 were fully satisfied and deployed as planned.
  6. Teliacompany representative — Reported daily linting deployment with digicert/pkilint to verify S/MIME certificate compliance and stated remedial actions were completed.
  7. Teliacompany representative — Requested the incident be closed, stating there were no further questions and all planned actions were completed.
  8. Mozilla representative — Stated the bug would be closed the next day (2024-01-26).
Participants
Teliacompany representative Mozilla representative
External References
Similar Local Cases
#1828105 RESOLVED Certificate Misissuance Opened 2023-04-14 · Closed 2023-06-30 · 100% similar
Telia: Misissued certificate - wrong OrganizationName value "Hair 8 Brains"
#1896108 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-05-10 · Closed 2024-09-06 · 97% similar
Telia: Certificates Issued with lower case value in subject:countryName
#1859314 RESOLVED Self Reported Incident Certificate Misissuance Opened 2023-10-16 · Closed 2024-01-26 · 96% similar
Telia: TLS certificates issued in violation of TLS BR v2.0.1
#1920659 RESOLVED Certificate Misissuance Self Reported Incident Opened 2024-09-24 · Closed 2024-12-06 · 96% similar
Telia: S/MIME Certificate issued to expired domain
#1940957 RESOLVED Certificate Misissuance Self Reported Incident Opened 2025-01-10 · Closed 2025-06-20 · 96% similar
Telia: TLS OV certificate with subject countryName and localityName mismatch
#1969036 RESOLVED Certificate Misissuance Opened 2025-05-28 · Closed 2025-10-31 · 90% similar
Telia: TLS incorrect AIA caIssuer URI and incorrect CDP
#1738207 RESOLVED Certificate Misissuance Opened 2021-10-28 · Closed 2023-02-22 · 89% similar
Telia: Issued three precertificates with non-NIST EC curve
#1528261 RESOLVED Certificate Misissuance Opened 2019-02-15 · Closed 2023-02-22 · 82% similar
Telia: Misissued certificate - FQDN without domain part (e_dnsname_not_valid_tld)

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action