← NAVER Cloud Trust Services cases
Bugzilla #1866448 Certificate Misissuance Incident

NAVER Cloud Trust Services: DV Certificate issued with improperly validated

RESOLVED FIXED NAVER Cloud Trust Services
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

NAVER Cloud Trust Services reported a misissuance of a Domain Validation (DV) certificate due to improper validation during testing of their new certificate issuance service, NCP Certificate Manager. The certificate was issued on November 24, 2023, after a QA team member inadvertently accessed an approval link in an email, leading to a bypass of standard validation procedures. Upon realizing the error, NAVER revoked the certificate immediately and initiated an investigation. They identified the root cause as excessive access rights granted to the QA team and have since implemented measures to prevent recurrence, including modifying the email approval process. The incident has been resolved with no further misissuance found.

Model: gpt-4o-mini Generated: 2026-06-13 20:55 UTC Revised: 2026-06-16 18:37 UTC Confidence: 0.90 26 comments
Chronology
  1. A DV certificate was improperly validated and issued.
  2. The certificate was revoked immediately upon discovery of the issue.
  3. NAVER implemented changes to the email approval process to enhance security.
Thread Activity
  1. Navercorp representative — NAVER Cloud Trust Services inform that a DV certificate was improperly validated and issued.
  2. Navercorp representative — An incident report was posted detailing the misissuance and corrective actions.
  3. Navercorp representative — NAVER confirmed that all analysis and actions have been completed.
Participants
Navercorp representative Community commenter Mozilla representative
External References
Similar Local Cases
#1845269 RESOLVED Certificate Misissuance Incident Opened 2023-07-25 · Closed 2023-09-29 · 100% similar
NAVER Cloud Trust Services: commonName not in SAN
#1908128 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-07-16 · Closed 2024-08-28 · 97% similar
NAVER Cloud Trust Services: Certificate issued with incorrect OCSP URI in AIA
#1908130 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-07-16 · Closed 2024-08-28 · 97% similar
NAVER Cloud Trust Services: Incorrect keyUsage for ECC certificate
#1785865 RESOLVED Certificate Misissuance Opened 2022-08-18 · Closed 2024-05-09 · 79% similar
NAVER Cloud Trust Services: DV certificate issued with no subject alternative name extension
#1717357 RESOLVED Certificate Misissuance Incident Opened 2021-06-20 · Closed 2023-02-22 · 79% similar
Actalis: Issuance of intermediates after 2020-08-20 that do not comply with Mozilla Policy and the Baseline Requirements
#1894054 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-04-29 · Closed 2024-07-03 · 78% similar
SwissSign: MPKI step-up process sets wrong JoI Locality
#1932973 RESOLVED Certificate Misissuance Incident Opened 2024-11-22 · Closed 2025-04-07 · 78% similar
SSL.com: CAA Empty set handling results in Wildcard issuance
#1651026 RESOLVED Certificate Misissuance Incident Remediation Tracking Opened 2020-07-07 · Closed 2023-02-22 · 78% similar
Izenpe: certificate issued to internal domain

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action