← Buypass cases
Bugzilla #1864204
Ca Certificate Compliance
Buypass: TLS certificates with incorrect Subject attribute order
RESOLVED
FIXED
Buypass
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
Buypass reported a compliance issue involving 591 TLS certificates issued since September 15, 2023, which had an incorrect relative order of Subject attributes, violating CA/B Forum Baseline Requirements. The issue was discovered during a self-audit on November 10, 2023, prompting Buypass to immediately halt further certificate issuance. They corrected the error and resumed issuance after ensuring compliance. Buypass plans to revoke all affected certificates and has provided a detailed incident report outlining the timeline and root cause analysis.
Chronology
- Buypass discovered incorrect Subject attribute order during a self-audit.
- Buypass submitted a full incident report detailing the compliance issue.
Thread Activity
- Buypass — Preliminary report submitted regarding the incorrect Subject attribute order.
- Buypass — Full incident report submitted detailing the compliance issue and corrective actions.
- Buypass — Confirmed inclusion of digicert/pkilint in the certificate issuance process.
- Mozilla representative — Indicated intention to close the bug.
Participants
Buypass
Internet Security Research Group
Mozilla representative
External References
Similar Local Cases
Buypass: Domain validation method using externally operated DNS tools
Buypass: Domain validation method using not allowed domain contact
Asseco DS / Certum: S/MIME certificates with error in subjectAlternativeName
Chunghwa Telecom: Wrong Extended Key Usage setting by GTLSCA
Entrust: S/MIME mailbox address not in subjectAltName
IdenTrust: S/MIME certificates issued in violation of New S/MIME Baseline Requirements v1.0
Entrust: S/MIME mailbox address case mismatch between subject and subjectAltName
NetLock: Replacement of enduser certificates after the EVGL 1.7.4 self-audit