← SwissSign AG cases
Bugzilla #1860750
Certificate Misissuance
SwissSign: EV code in JurisdiktionStateOrProvinceName
RESOLVED
FIXED
SwissSign AG
AI Summary
SwissSign AG identified a compliance issue regarding the use of ISO 3166-2 codes instead of the full names for the 'jurisdictionStateOrProvinceName' field in their EV certificates. This misissuance was discovered during an internal review initiated by an employee's query. Although the certificates were deemed non-compliant with EV Guidelines, the risk to the ecosystem was assessed as low since consumers typically do not scrutinize this field. SwissSign has since implemented corrective actions, including revocation of affected certificates and adjustments to their issuance processes.
Chronology
- Internal employee raises question about EV jurisdictionStateOrProvinceName field
- Product manager discovers non-compliance and compliance incident raised
- Bugzilla posted and corrective actions initiated
Participants
raffaela.achermann@swisssign.com
dzacharo@harica.gr
roman.fischer@swisssign.com
ryandickson@google.com
bwilson@mozilla.com
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
GDCA: Issuance of SSL/TLS certificates with Non-critical Basic Constraints
iTrusChina: Issuance of certificates using keys previously reported as compromised
SwissSign: EV JurisdictionStateOrProvinceName - one certificate not selected for revocation
IdenTrust: unintended creation of a Root CA certificate
Sectigo: Subject field with unvalidated information included in certificates
SwissSign: Misissuance of Intermediate Certificates because of incorrect organizationIdentifier
SwissSign: Misissuance of Leaf Certificates because of incorrect postcode
SwissSign: Domain validated certificate but with stateOrProvinceName