← SwissSign AG cases
Bugzilla #1874196 Certificate Misissuance

SwissSign: difference in upper and lower case between CN field and SAN

RESOLVED FIXED SwissSign AG
AI Summary

SwissSign identified a mis-issuance issue involving 44 certificates due to a discrepancy between the Common Name (CN) field and the Subject Alternative Name (SAN). The problem was reported by Ben Wilson, leading to an immediate investigation and revocation of the affected certificates. The root cause was traced to a bug in the issuance workflow that allowed the process to continue despite negative linting results. A fix was implemented on February 20, 2024, and an automatic alarm system for future mis-issuances was successfully tested on March 19, 2024.

Model: gpt-4o-mini Generated: 2026-06-13 20:49 UTC Confidence: 0.95
Chronology
  1. Implementation of the Update that introduced the bug
  2. First mis-issued certificate
  3. Last mis-issued certificate
  4. Fixing conversion of big letters to small letters in the interface
  5. Email from Ben Wilson received
  6. Compliance confirms mis-issuance and starts mis-issuance process
  7. Implement fix for bug
  8. Automatic alarm for mis-issuance process successfully tested
Participants
Sandy Balzer Ben Wilson Aaron Gable Mathew Hodson
External References
Similar Local Cases
#1914023 RESOLVED Certificate Misissuance Opened 2024-08-20 · Closed 2025-04-03 · 68% similar
SwissSign: S/MIME LCP not-permitted key usage
#1894054 RESOLVED Certificate Misissuance Opened 2024-04-29 · Closed 2024-07-03 · 66% similar
SwissSign: MPKI step-up process sets wrong JoI Locality
#1916489 RESOLVED Certificate Misissuance Opened 2024-09-03 · Closed 2025-03-18 · 65% similar
SwissSign: LDAP URL still in CRL distribution point (CDP)
#1848854 RESOLVED Certificate Misissuance Opened 2023-08-15 · Closed 2024-03-27 · 62% similar
SwissSign: S/MIME LCP: CN with values other than email address
#1766255 RESOLVED Certificate Misissuance Opened 2022-04-25 · Closed 2023-02-22 · 61% similar
SwissSign: Mis-Issuance of S/MIME certificates
#1613334 RESOLVED Certificate Misissuance Opened 2020-02-05 · Closed 2023-02-22 · 60% similar
SwissSign: Misissuance with mispellings in Location for a number of Certificates
#1876771 RESOLVED Certificate Misissuance Opened 2024-01-26 · Closed 2024-02-08 · 60% similar
SwissSign: modified fields were not saved into certificates and resulted in miss-issuance
#1691704 RESOLVED Certificate Misissuance Opened 2021-02-09 · Closed 2023-02-22 · 59% similar
SwissSign: Certificate with key length 4098 bit

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action