← Buypass cases
Bugzilla #1864204 Ca Certificate Compliance

Buypass: TLS certificates with incorrect Subject attribute order

RESOLVED FIXED Buypass
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Buypass reported a compliance issue involving 591 TLS certificates issued since September 15, 2023, which had an incorrect relative order of Subject attributes, violating CA/B Forum Baseline Requirements. The issue was discovered during a self-audit on November 10, 2023, prompting Buypass to immediately halt further certificate issuance. They corrected the error and resumed issuance after ensuring compliance. Buypass plans to revoke all affected certificates and has provided a detailed incident report outlining the timeline and root cause analysis.

Model: gpt-4o-mini Generated: 2026-06-13 21:26 UTC Revised: 2026-06-16 18:18 UTC Confidence: 0.85 19 comments
Chronology
  1. Buypass discovered incorrect Subject attribute order during a self-audit.
  2. Buypass submitted a full incident report detailing the compliance issue.
Thread Activity
  1. Buypass — Preliminary report submitted regarding the incorrect Subject attribute order.
  2. Buypass — Full incident report submitted detailing the compliance issue and corrective actions.
  3. Buypass — Confirmed inclusion of digicert/pkilint in the certificate issuance process.
  4. Mozilla representative — Indicated intention to close the bug.
Participants
Buypass Internet Security Research Group Mozilla representative
External References
Similar Local Cases
#1839305 RESOLVED Ca Certificate Compliance Opened 2023-06-20 · Closed 2024-06-30 · 96% similar
Buypass: Domain validation method using externally operated DNS tools
#1838421 RESOLVED Ca Certificate Compliance Opened 2023-06-14 · Closed 2024-06-30 · 90% similar
Buypass: Domain validation method using not allowed domain contact
#1879845 RESOLVED Ca Certificate Compliance Opened 2024-02-12 · Closed 2024-10-02 · 81% similar
Asseco DS / Certum: S/MIME certificates with error in subjectAlternativeName
#1887096 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2024-03-22 · Closed 2024-09-06 · 78% similar
Chunghwa Telecom: Wrong Extended Key Usage setting by GTLSCA
#1906467 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2024-07-05 · Closed 2025-05-13 · 77% similar
Entrust: S/MIME mailbox address not in subjectAltName
#1853783 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2023-09-18 · Closed 2025-03-20 · 71% similar
IdenTrust: S/MIME certificates issued in violation of New S/MIME Baseline Requirements v1.0
#1906470 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2024-07-05 · Closed 2025-05-13 · 71% similar
Entrust: S/MIME mailbox address case mismatch between subject and subjectAltName
#1680378 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-12-02 · Closed 2023-02-22 · 71% similar
NetLock: Replacement of enduser certificates after the EVGL 1.7.4 self-audit

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action