← Buypass cases
Bugzilla #1864204
Certificate Problem Report
Buypass: TLS certificates with incorrect Subject attribute order
RESOLVED
FIXED
Buypass
AI Summary
Buypass issued 591 TLS certificates with an incorrect relative order of Subject attributes, violating BR section 7.1.4.2. The error was identified during a self-audit on November 10, 2023, leading to an immediate halt in issuance. Affected certificates will be revoked, and the issue has been resolved with corrected issuance processes. A full incident report was provided detailing the timeline and root cause analysis.
Chronology
- Certificate profile changes in BR 2.0.0 came into effect.
- Incorrect Subject attribute order discovered; issuance stopped.
- Full incident report submitted.
Participants
Mads Henriksveen
External References
Similar Local Cases
Buypass: Insufficient Serial Number Entropy
Buypass: Missing NCA identifier in cabfOrganizationIdentifier in PSD2 QWACs
Buypass: Illegal Business Category in a PSD2 QWAC
Buypass: PSD2 QWAC with RSA modulus not divisible by 8
Buypass: Domain validation method using not allowed domain contact
Buypass: Using an external DNS Resolver for DNS lookups
Buypass: intermediate certificates not revoked within BR time period
Buypass: Failure to revoke PSD2 QWACs within mandated 5 days